|
Sofizar Finds Security Flaw in Google AdWords Pay Per Click Service
16 January 2006 Sofizar Inc, a company specializing in Click Fraud Detection Services announced today that it has identified a vulnerability in Google's Pay Per Click (PPC) location based advertisements. The Google location based service is meant to display Pay Per Click (PPC) advertisements only in the advertiser designated locations. However, a back door allows a malicious user or automated programs in a non designated area to click on the advertisement, potentially causing grievous losses. Furthermore, Google charges the advertisers for these clicks, even though Google does not record the advertisement impression. This vulnerability has been reported to Google. The location based Google service is designed to display targeted advertisements to users from a certain region. For example, a ticket broker ( http://www.ticketnest.com/theater-tickets/wicked-tickets ) who needs to sell wicked tickets in New York City does not want her advertisement to be displayed in New Delhi. The pay per click advertisements to a non target audience can be extremely costly, and AdWords PPC advertisers use Google's facilities to designate countries (and in some cases cities) where their advertisements can be displayed. However, this vulnerability allows a hacker in Beijing to see and click on advertisements meant for a Las Vegas audience. Some advertisers pay up to $35 every time a user clicks on their advertisement, and a hacker can run up the tab for such advertisers quite fast. Sofizar's internal testing shows that Google not only charges for these clicks, but due to a software glitch in Google's reporting interface, does not record the impression. «PPC advertisement has become very popular due to their instant traffic results, and control over the composition of the traffic» said Ron Arthur, Program Manager of Sofizar managed service. «Given that there is about $7 Billion at stake with Google PPC advertising in 2006, malicious hackers are always on the look out to get a piece of the pie. An advertiser may feel secure in the knowledge that his advertisements are being displayed only in the US, while his advertisements may be getting unwanted clicks (and a massive bill) from a hacker in East Europe.» «There is essentially an arms race between the click fraudsters and us,» said Zafar Khan, CEO of Sofizar. «We see ever insidious tactics by hackers to deplete the budget of advertisers, and unless the advertiser is really keeping close tabs on their PPC advertising they are a prime target for fraud. The location based vulnerability allows hackers to fly under the radar, and hit unsuspecting advertisers. We have reported this flaw to Google and we are confident that they will fix the glitch in their software. Our previous experience in dealing with Google customer support regarding glitches has been outstanding.» Testing methodology used: The vulnerability was tested on Sofizar's test account ( http://www.ticketluck.com) where a US targeted AdWords campaign for a keyword with no searches was selected. Sofizar's testers in their test center in Pakistan then used the back door to display and click their test advertisement (http://www.google.com/search?sourceid=navclient&ie=UTF-8&rls=GGLD,GGLD:2005-19,GGLD:en&q=Minimalist+Jukebox%3A+Reich+Tickets&gl=us) that was only supposed to show in the US. When the account was checked, Google had charged Ticket Luck campaign for the click, even though it did not report the impression. About Sofizar: Sofizar uses its traffic analysis and pattern matching software to detect fraudulent PPC clicks. This software is adaptive, and stores patterns for certain websites as well as deviations from recognized patterns. Sofizar manually audits the accounts which are flagged by this software as possible frauds and then works with search engines to obtain refunds and credits against future advertising spending. Sofizar proactively looks for vulnerabilities in Overture and Google, in order to better protect its clients. We are keeping a close eye on this issue, and will be regularly updating our test results, as we get more data. The latest results can be found at: http://www.sofizar.com/press-release-google.php
Source: prweb
All trademarks and copyrighted information contained herein are the property of their respective owners.
Related Internet Articles
|
 | Unlimited Domain Hosting Only $10 a Month Founded in 2002, Hostgator.com, LLC has quickly grown from its humble beginnings in Boca Raton, Florida into one of the most respected names in the web hosting industry. Renowned for exceptional customer support and unrivaled in terms of customer satisfaction, Host Gator is poised to take the lead in the highly competitive and densely populated world of web hosting providers.
For more information!
Click Here |
|
|
 | Got Root?! 1&1 Dedicated Servers starting at $99 mo. We guarantee the highest product quality, top security, and unshakeable reliability. 1&1’s advanced Data Centers have been built from the ground up using the most advanced technology available, giving our global network a strength that is beyond doubt. The power and stability of 1&1’s systems allows us to be first to market with web products that are innovative yet dependable.
For more information!
Click Here |
|
|
 | Get a full dedicated server starting at just $29.95! ServerPronto is a dedicated hosting subsidiary of Infolink, one of a few profitable Data Center Corporations in the world. From it's beginning in January 1999, Infolink served the "Value Orientated" segment of the Internet market. Not by offering a sub-standard product at a low price, but by offering a top-quality, feature rich product at an incredible price. Since the beginning Infolink has enjoyed dramatic growth while other's in the industry have suffered. We operate our own network in the USA and maintain redundant Fiber Optic Rings which allow us to directly peer with Tier 1 Internet Backbones.
For more information!
Click Here |
|
|