Ads often have something like this attached to the end:
load("https://adserver/track.gif?{stuff}&_=" + Math.random())
My ad server collected multiple tracking pixels -- for various events and after five pixels I could fingerprint the browser (Firefox, Chrome, MSIE, etc) and identify someone fiddling with the user agent string, or using a proxy server to mask this information.