Results 1 to 9 of 9

Thread: DNS skimming? How does this scam work.

  1. #1
    Xtreme Owner Charles Wirth's Avatar
    Join Date
    Jun 2002
    Location
    Las Vegas
    Posts
    11,653

    DNS skimming? How does this scam work.

    A few days ago a domain appeared on my adsense from google that was not me.

    https://www.networksolutions.com/who...stemsforum.com

    I did not set that up but I am trying to figure out why it was made and how it appeared on my pay sheet with $0.0 paid.

    The only way he would be able to appear on my pay sheet is if they copied my ad code and served it from that domain.

    If you go to the domain it appears that it just forward to here but I think more might be going on.

    The domain was registered at enom inc, the worst registrar on the net known for don't care attitude.

    Ideas?
    Intel 9990XE @ 5.1Ghz
    ASUS Rampage VI Extreme Omega
    GTX 2080 ti Galax Hall of Fame
    64GB Galax Hall of Fame
    Intel Optane
    Platimax 1245W

    Intel 3175X
    Asus Dominus Extreme
    GRX 1080ti Galax Hall of Fame
    96GB Patriot Steel
    Intel Optane 900P RAID

  2. #2
    Xtreme Member
    Join Date
    May 2009
    Location
    Krypton, Hawaii
    Posts
    363
    I explain it as soon as I can explain how a complete medical website hosted itself on my other godaddy server.

  3. #3
    I am Xtreme
    Join Date
    Dec 2002
    Posts
    5,931
    If they copied your ad code how would they get paid? I see your point -That's the only reason I could see someone forwarding that domain to you. Will ponder this...

  4. #4
    Xtreme Owner Charles Wirth's Avatar
    Join Date
    Jun 2002
    Location
    Las Vegas
    Posts
    11,653
    According to Google that site paid me for my ads, I contacted google days ago, I got the auto reply to wait.
    Intel 9990XE @ 5.1Ghz
    ASUS Rampage VI Extreme Omega
    GTX 2080 ti Galax Hall of Fame
    64GB Galax Hall of Fame
    Intel Optane
    Platimax 1245W

    Intel 3175X
    Asus Dominus Extreme
    GRX 1080ti Galax Hall of Fame
    96GB Patriot Steel
    Intel Optane 900P RAID

  5. #5
    I am Xtreme
    Join Date
    Dec 2002
    Posts
    5,931
    0.0$ sounds like it's a really winner for you! I use gsuite at my work and sometimes it's frustrating to hear back from them that your bug is just the system working as it's supposed to. That being said, no better player in the market....

  6. #6
    Xtreme Addict
    Join Date
    Sep 2010
    Location
    US, MI
    Posts
    1,680
    I came across this info today I thought about ya, not sure how relevant it is:
    http://boards.4chan.org/pol/thread/139159224

  7. #7
    I am Xtreme
    Join Date
    Dec 2002
    Posts
    5,931
    That is very interesting. Click here to see what these celebrities look like now.

  8. #8
    Xtreme Owner Charles Wirth's Avatar
    Join Date
    Jun 2002
    Location
    Las Vegas
    Posts
    11,653
    I got paid a penny from the ghost site, can anyone capture code from that sites redirect?
    Intel 9990XE @ 5.1Ghz
    ASUS Rampage VI Extreme Omega
    GTX 2080 ti Galax Hall of Fame
    64GB Galax Hall of Fame
    Intel Optane
    Platimax 1245W

    Intel 3175X
    Asus Dominus Extreme
    GRX 1080ti Galax Hall of Fame
    96GB Patriot Steel
    Intel Optane 900P RAID

  9. #9
    Xtreme Addict
    Join Date
    Sep 2010
    Location
    US, MI
    Posts
    1,680
    I think it's to late now, I don't know anything really about this sorta stuff.
    Other then politics originally drove this, they were trying to hurt google's pocketbook by messing over there adsense.

    I'm guessing it's the reason why a while back the site would continuously load dynamically over and over.
    Don't know though.
    I do know it's still complaining about it having a broken https when I sign in, it's in http insecure mode right now and has been for months.
    I don't think I have to worry about mitm attacks here though tbh.
    It would be one thing if it was fb or tw, but...

    Still, people do target this site from time to time it seems.
    All it would take is for someone to get in the range of an admins wifi, and wait for them to log in or use the site.
    But I don't think anyone is going to go that far.
    I wonder why they hack this site anyways...
    Do they think we pass datasheets in our pm's or something?
    Sure I've passed info on say afterburner's voltage limits, I think, maybe...?, in pm, but that's not anything someone couldn't figure out on there own how to writing your own oem file, the author slipped it into the public once that's how I found out.
    So I dn wtf...

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •