Spammers started to hit GitHub?
github.com
github.com
I still do not understand how it makes them money, I think it's just an endless chain of people falsely thinking others are successful with it so they try to do it too and the cycle continues.
When I saw this post the page had 404d. However, the page was still active in the Google cache[1]
It is not just Github being targeted, a lot of other large websites with user generated content are also being spammed with this content[2][3]
The spammers are linking the content to blogspot blogs so that they can: 1. hide the referrer from their affiliate program (to prevent getting banned for spamming) 2. to utilize the temp increase in search engine rankings 3. save money on domains for one-off usage
Since the "live stream" is just a one-off game that will only be popular/trending for 1-3 days in which period the spammers will use a lot of macro scripts/bots to spam these websites. Believe it or not, even a "nofollow" link can give you an advantage in search rankings. They spam them to death in the "popular period" and then bank money from the affiliate program[4]
[1]http://webcache.googleusercontent.com/search?q=cache%3Ahttps... [2]http://shine.yahoo.com/author-blog-posts/watch-38-enjoy-flor... [3]http://webcache.googleusercontent.com/search?q=cache%3Awww.f... [4]http://www.officialtvstream.com.es/passport/signup.php?price...
Actually, in most cases, these reasons have little to do with it. For the most part, the pages are created on public sites because the links are spammed on social networks, and those networks quickly block postings with the same links over and over again. So, if you can create hundreds of different URLs with the same landing page, you can have hundreds of times the spam posts go through and not be blocked. Most of these guys don't bother with private domains because social networks will quickly issue a blanket block to all posts containing links to untrusted domains that have been reported to them for spam, but they will never issue a blanket block for a site like Github or Facebook. So the links last longer.
As to the specifics:
1) 1. hide the referrer from their affiliate program (to prevent getting banned for spamming). There are much easier and reliable ways to not only hide, but entirely change, the referer. See http://www.contentgeneration.org/cpa-redirector-2/
2)to utilize the temp increase in search engine rankings These sites aren't meant for that. Whether they link from the landing page straight to the affiliate link, or they go to a lander that is used to change the referer, they don't care about the search rankings of the links.
If you had to speculate: How much money?
(I know, it all depends, etc. But I was just hoping to get a rough idea of the order of magnitude here.)
Now, as you can see from Google Trends[1] some of these get very popular and trend once pretty much every year. In the second comparison, I've compared the search terms with a term I know is definitely popular to get relative popularity of the terms [2]. Comparing these two terms I can get an idea of the amount of traffic these website would get in the time period. I would estimate that the "big spammers" would easily get around 250k-500k uniques from multiple sources (spamming, mass advertising, social media, botnets etc).
Assuming they get paid $2 every signup, and have a conversion rate of 1.5% with 300k uniques, it would bank them around $9k, of course I'm only talking about the big guys here who have done this for a long time.
In general, I would say that the following is correct:
Upper quartile average: $1-3k per day for a few days
Lower quartile average: $50-60 per day for a few days
Quick edit: It should also be noted that for these live games over 95% of the traffic will be from the USA hence the large profits.
---------
[1]http://www.google.com/trends/explore#q=Iowa%20vs%20Michigan%...
[2]http://www.google.com/trends/explore#q=Iowa%20vs%20Michigan%...
This behavior is inherent to human nature, and presumably to everyone here who calls themselves a hacker. That Google doesn't "like" what I do has no moral or legal weight. The same goes for sites that accept user-generated content.
Obviously not everybody who's a spammer is good at it or a true hacker, but I would venture a guess that most hackers are blackhat if they do SEO, simply because they see this as a system that can be exploited with controlled heuristic testing as apposed to some superfluous tools and a whack community a la seoMoz.org
And it's not a zero-sum game. Google is forced to improve their natural language processing capabilities, their ability to execute more computationally expensive processing on massive amounts of content, so on and so forth, to try and keep up and provide a legitimate product.
So back to the spamming; Any site that allows you to put a link on it is a target for seo, of course. Maximizing c-class IP diversity among links is important. But more importantly, these pages are usually Tier-1 to Tier-2 in link schemes as it's effective to point the low level forum spam at user-content generated sites with strong domain authority and funnel the juice to your primary site. They're basically just buffers.
How long does it last? Varies greatly on how you're promoting it, the niche its in, etc. It doesn't always have to be "pump and dump" - I have multiple blogs over a year old that are alive and producing $1,200-$2,000 month each with almost no effort. When you can create just one of those blogs with about 10 hours worth of work (in total), there's obviously money to be made. And if you can write all of your own software to automate it, you can pretty much just "print money."
The key idea is where do you live: if I'm living in a poor country where average salaries can vary from $50 to $400 per month, imagine how much I can make by send viagra spam by just sending emails to doing hard physical job ? For us it's not worth even doing it as a hobby. For some people, it's damn profitable, just take the case of Nigerian scammer, convincing someone to send him $500. He's doing that every day, if he can scam one "wealthy" person to do it once per month, it's damn profitable. Yeah, this isn't really a shiny way to make profit, but you may understand the motivation behind it.
It makes money from a pure economies of scale situation. When your marginal cost per "ad" is essentially zero, you can ship out a sufficiently large number of such ads that even the smallest percentage of recognition by the targets results in thousands or millions of return inquires/clicks/etc. I.e., if it cost $10 for 1 billion views, and only 0.0001% respond, that is 1000 responses. Effectively only costing one cent per response. If you make ten cents per response, you have made $100 on your $10 investment.
Couple that with the fact that a computer did the "work" and it is an easy money machine.
It is not practical to operate any kind of website that allows users to post things without some form of spam protection. For small sites, email verification or text classification will do the job by itself. Traditional captchas are fairly ineffective, but written questions like "what color rhymes with true?" seem to work pretty well for smaller sites.
Bigger sites dealing with a larger volume of traffic almost always require regular human intervention, curated IP block lists, stealth banning and the like.
If you want to get Google's cached version of a webpage, just type
cache:[url]
e.g.: cache:https://github.com/quartzjer/TeleHash/issues/5
in the search bar and press return.I know, it's a petty technicality. Safari says it can't open the specified address, and Firefox doesn't understand the URL. I'm even more certain IE will explode if I was to try, but I can't at the moment. From what I remember, IE can't even parse a raw IP address without explicitly putting http:// in front of it.
CAPTCHA only security is fantastic for spammers.
Or you can buy OCR software that plugs in to your bots; e.g. captchasniper.com
Captcha'd targets are usually higher-quality and more valuable as there is some economic cost of posting to it.
Thanks God for http://bugmenot.com!
I'm not sure if there is a way to report them, there is nothing no the GH contact form.
Have you notified them before posting this?
I'm not sure why you say prior notification is proper etiquette in this circumstance. It's equivalent to pointing out a grammar mistake in a blog post. Not particularly interesting, but not malicious.
I'm not talking about "responsible disclosure" and I'm not sure why people assumed I do.
If I see that a person has their fly open, I'd go and discretely alert them of that. Similarly, if someone has a note saying "I am stupid" taped to their back (which I think is a good analogy to what the spam on github is), I would do the same.
I wouldn't go shouting "hey, github has an 'I am stupid' sign taped on their back" in town square, which is what posting it on HN amounts to.