It was discovered years ago because:
* Their IP stack was acting like Linux[1]
* Their flash player said "I'm Linux"
* Their user agent said other things (random user agents)
* Their DNS traffic was going UK, but the hosts were coming out of the US
It was discovered years ago because:
* Their IP stack was acting like Linux[1]
* Their flash player said "I'm Linux"
* Their user agent said other things (random user agents)
* Their DNS traffic was going UK, but the hosts were coming out of the US
I imagine somewhere in MethBots virtual DOM emulation they got sloppy and ran code (JS) from the server. Using metaprogramming plus some output they could predict they could use runtime reflection and inspect server side JS object.
>
On page 19 in the The Methbot Operation report they state that ‘White Ops detection technology was able to use a JavaScript language feature called “reflection” to gather extensive, detailed information about its inner workings.’
I have personally never heard about JavaScript reflection before, but it appear to be a debug method for one object to dump information or data about another object.
Maybe the White Ops software loaded some JavaScript that was able to dump much of its environment and send it back to White Ops?
let test = function() { return "hello";}
test.toString()
returns "function() { return "hello";}"
It's not too difficult to imagine that pairing that with some JS parsing would allow you to slowly crawl your way around an app and gather the app structure. Crazy, and fascinating idea.* list of botnet infected IPs participating in ad fraud
* list of offending/incompetent SSP blindly accepting forged requests
There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent.
The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be at a significant (fiscal) disadvantage.
I'd like to get in touch with anyone ad network/SSP that wants to go first.
> lists of botnet infected IPs participating in ad fraud
This won't be enough.
A popular "audience extender" is to use an iframe containing your site as an ad tag, and run it on your display network. Unless you have been using an ad blocker for the last ten years (and maybe even then), it's very likely your IP address has been used in ad fraud.
> lists of offending/incompetent SSP blindly accepting forged requests
Google facilitates an enormous amount of ad fraud, but media buyers have to buy from Google because nobody else sells Google search ads (except, I suppose, the injection people...)
Yahoo purchased a company who was selling video ads that were muted using uncommon AS3 mixer controls.
I think a much shorter list would be the media suppliers that don't have ad fraud on them and don't facilitate ad fraud. You'll find such a list below.
var st:SoundTransform = new SoundTransform(1.0);
st.leftToLeft = st.leftToRight = 0.0;
st.rightToLeft = st.rightToRight = 0.0;
SoundMixer.soundTransform = st;
Mutes the audio, but if a VPAID component naively checks: SoundMixer.soundTransform.volume
they will get 1.0. Most don't even bother checking though.As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?
Someone has some "sites" that they show to an ad network or an advertiser and tries to sell the impressions on those sites. They receive "ad tags" in exchange, and the theory is that users are exposed to the ads shown by those ad tags, and the advertiser is satisfied.
However, once they have "ad tags", they can do whatever they want with them. They can find the URL signal that represents "give me money" and arrange to fire that signal.
> As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?
No.
The Media Rating Council[1] was endowed by congress with special powers that allow participants to talk to each other antitrust protections kicking in, but these conversations are extremely non-productive.
Thanks for the code above. What was the company name? never heard of it.
And yet they're still active with the same tech stack.
When three-letter television companies will buy an audience extender from one of these shady guys rather than tell the advertiser that they don't have as much traffic as they projected, you don't really even need to worry about detection.
There exist passive techniques powerful enough to really map these kinds of actors out thoroughly, however the industry has been reticent to stop it because everyone from Viacom to Google has facilitated ad fraud, and there's this fear that stopping things too abruptly will cause advertisers to lose faith in this (still nascent) $60 billion dollar industry (US numbers).
All the other techniques require JavaScript and/or AS3 and are thus subject to modification by these kinds of sophisticated attackers. The only real way to do JavaScript in these cases is to change it often enough and run enough parallel versions that the attacker cannot keep up.
The level of programming skill in the "industrial scale botting" community is high. Top tier botters can easily get into +$100k club if they were doing whitehat stuff.
Bot detection, ad auditing, antifraud systems
It reminds me of ns.cnet.com