Affiliate Marketing
Forum Search

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 27-09-06
Paul Wright's Avatar
Fishboy
 
Join Date: Jan 2005
Location: London
Posts: 1,657
Thanks: 5
Thanked 8 Times in 4 Posts
Paul Wright is an unknown quantity at this point
  Help decloaking the cloaked affiliate links.

My turn for help

Can somebody please explain to me what’s going on here. It’s some kind of cloaking.

If you build a webpage using the following code:


HTML Code:
<html>
<head>
<title>Buy Cosmetics</title>
<script>window.status = ' ';</script>
<script>document.write(unescape("%3c%66%72%61%6d%65%73%65%74%20%62%6f%72%64%65%72%3d%30%20%66%72%61%6d%65%73%70%61%63%69%6e%67%3d%30%20%66%72%61%6d%65%62%6f%72%64%65%72%3d%30%20%72%6f%77%73%3d%2a%3e%3c%66%72%61%6d%65%20%6d%61%72%67%69%6e%77%69%64%74%68%3d%30%20%6d%61%72%67%69%6e%68%65%69%67%68%74%3d%30%20%73%72%63%3d%68%74%74%70%3a%2f%2f%77%77%77%2e%62%75%79%63%6f%73%6d%65%74%69%63%73%2e%61%74%2f%62%6c%75%65%62%61%72%72%61%63%75%64%61%3e%3c%2f%66%72%61%6d%65%73%65%74%3e%3c%6e%6f%66%72%61%6d%65%73%3e"))</script>
<script>document.write(unescape("%3c%2f%6e%6f%66%72%61%6d%65%73%3e"))</script>
</head>
</html>
Open it up in your browser you’ll see that this is cloaking a redirect through an affiliate link that goes to the buycosmetics.com site.

What weird is that if you then view source you don’t see the buycosmetics.com code but some scrambled text.

I’m guessing that I’m missing something completely obvious here but what is it?

Cheers
Paul.
__________________
Paul Wright | Affiliate Marketing Director | Mediaedge:cia
e: paul.wright@mecglobal.com | t: 0207 803 2976 | m: 07834 697 130
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 27-09-06
Super Moderator
 
Join Date: Aug 2003
Posts: 1,984
Thanks: 1
Thanked 1 Time in 1 Post
Fraser seems to know their stuff
It looks like it's loading up the affiliate link in an iframe but in a disguised way. You can use

http://www.albionresearch.com/misc/urlencode.php

to decode all the coded bit.
__________________
Fraser

Affiliate Blog & Podcast
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 27-09-06
Gavinio's Avatar
True Blue
 
Join Date: Feb 2005
Location: Sydney
Posts: 978
Thanks: 9
Thanked 3 Times in 3 Posts
Gavinio is an unknown quantity at this point
It's just URL encoded isn't it?

Code:
<frameset border=0 framespacing=0 frameborder=0 rows=*><frame marginwidth=0 marginheight=0 src=http://www.buycosmetics.at/bluebarracuda></frameset><noframes>
PS I'm no techie so slap me if I'm stating the obvious.
__________________
Now with NEW! SHORTER! SIGNATURE!
If I post at funny hours, it's cos I'm in Oz!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 27-09-06
Frostie's Avatar
Moderator
 
Join Date: Aug 2003
Location: Wirral
Posts: 3,012
Thanks: 7
Thanked 13 Times in 6 Posts
Frostie is on a distinguished roadFrostie is on a distinguished road
Yeah

This translates to loading BuyCosmetics in an iFrame. The culprit in this case is;
http://www.buycosmetics.at/bluebarracuda

Any idea who BlueBarracuda is?
__________________
Affiliate Blog | Eco Friendly | Discount Codes - Exclusive codes = Inclusion in newsletter to 26,000 recipients
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #5 (permalink)  
Old 27-09-06
renegade's Avatar
Moderator
 
Join Date: Aug 2003
Posts: 3,221
Thanks: 85
Thanked 16 Times in 12 Posts
renegade seems to know their stuffrenegade seems to know their stuff
That looks like UUEncoded text in a javascript wrapper, I use a utility to encode email addresses on websites to help reduce spam.
__________________
Joe's CantBarsed Blog | Discount Codes
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 28-09-06
Paul Wright's Avatar
Fishboy
 
Join Date: Jan 2005
Location: London
Posts: 1,657
Thanks: 5
Thanked 8 Times in 4 Posts
Paul Wright is an unknown quantity at this point
Haha, congratulations, you've all passed the test.

The actual affiliate link used was a dummy account I use to test our affiliate programs and it was me who scrambled it using an online tool I found yesterday.

What I was trying to find out was what the heck was going on.. or how the tool worked... and as fraser kindly pointed out... how to unscramble it.

It's all going in my little black book under "things that people do to hide thier links".

Mucho gracias

Paul.
__________________
Paul Wright | Affiliate Marketing Director | Mediaedge:cia
e: paul.wright@mecglobal.com | t: 0207 803 2976 | m: 07834 697 130
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 28-09-06
Dynamoo's Avatar
Mooooo
 
Join Date: Dec 2003
Location: Somewhere in Bedfordshire
Posts: 1,382
Thanks: 0
Thanked 0 Times in 0 Posts
Dynamoo is an unknown quantity at this point
SamSpade for Windows is a great tool for investigating links. Although it wouldn't help with the Javascript issue, it's a useful tool for following them step-by-step.

A neat way of deobfuscating JS can be found in Follow the Bouncing Malware IX (scroll down to Doctor! No!). Basically, you wrap the whole thing up like this:

Quote:
In the above code, this can be accomplished by putting the following before the call to document.writeln(o):

document.write("<textarea cols=100 rows=100>");

and the following immediately after:

document.write("</textarea>");
Uh it's the kind of think I sometimes end up doing in my real life work.
__________________
This is not a signature.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Part One:What Does an affiliate Manager do all Day jess1 The Affiliate Marketing Lounge 32 26-03-08 06:55 PM
Affiliate site not listed on Dmoz.org here is why! supercod Website Promotion 32 14-03-08 12:31 PM
Will using 302 temp redirect for affiliate links affect Google SEO? MobileDealsNow Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 1 04-10-05 09:10 PM
New try, Networks vs In House allaffiliatepro The Affiliate Marketing Lounge 28 18-01-05 02:29 PM
Affiliate links stored in a database Nigel Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 4 07-01-04 02:46 PM


Affiliate Marketing RSS Feeds - Contact Us - Affiliate Marketing - Archive - Privacy Statement - Top

Content Relevant URLs by vBSEO 3.2.0 RC7