ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 1
ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 2

Ua hele lākou a hiki i ke kūkākūkā ʻana i ka hiki ke hoʻohana i nā mea hoʻokele UPS e kū i ka mea kānalua. E nānā kākou inā he kānāwai ka mea i ʻōlelo ʻia ma kēia paheʻe?

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Eia ka pane a ka FTC i ka nīnau, "Pono au e hoʻihoʻi a uku paha no kahi mea aʻu i kauoha ʻole ai?" - "ʻAʻole. Inā loaʻa iā ʻoe kahi mea āu i kauoha ʻole ai, aia iā ʻoe ke kuleana kānāwai e ʻae iā ia ma ke ʻano he makana manuahi." He kūpono paha kēia? Holoi au i koʻu mau lima no ka mea ʻaʻole oʻu akamai e kūkākūkā i kēlā mau mea.

Akā ʻo ka mea hoihoi, ʻike mākou i kahi ʻano i ka liʻiliʻi o ka ʻenehana a mākou e hoʻohana ai, ʻoi aku ka nui o ke kālā i loaʻa iā mākou.

Hoʻopili pūnaewele hoʻopunipuni

Jeremy Grossman: he paʻakikī loa ka hoʻomaopopo ʻana, akā ma kēia ala hiki iā ʻoe ke loaʻa i kahi kālā ʻeono. No laila, he loulou maoli nā moʻolelo a pau āu i lohe ai, a hiki iā ʻoe ke heluhelu kikoʻī e pili ana i kēia mau mea a pau. ʻO kekahi o nā ʻano mea hoihoi loa o ka scam pūnaewele ʻo ia nā scam pili. Hoʻohana nā hale kūʻai pūnaewele a me nā mea hoʻolaha i nā pūnaewele pili e hoʻokele i nā kaʻa a me nā mea hoʻohana i kā lākou mau pūnaewele no ka hoʻololi ʻana i ka ʻāpana o ka loaʻa kālā.

E kamaʻilio wau e pili ana i kahi mea i ʻike nui ʻia e ka poʻe he nui no nā makahiki, akā ʻaʻole hiki iaʻu ke ʻike i kahi ʻōlelo ākea e hōʻike ana i ka nui o ka pohō o kēia ʻano scam. I koʻu ʻike, ʻaʻohe hihia hoʻopiʻi, ʻaʻohe hoʻokolokolo kalaima. Ua kamaʻilio wau me nā mea hana ʻoihana, ua kamaʻilio wau me nā poʻe ʻoihana pili, ua kamaʻilio wau me ka Black Cats - manaʻo lākou a pau ua loaʻa i nā scammers ka nui o ke kālā mai ka hui.

Ke noi aku nei au iā ʻoe e lawe i kaʻu ʻōlelo no ia mea a e kamaʻāina i ka hopena o ka "haʻawina home" aʻu i hoʻopau ai i kēia mau pilikia kikoʻī. Ma luna o lākou, nā scammers "weld" 5-6-helu, a i kekahi manawa ʻehiku mau helu i kēlā me kēia mahina, me ka hoʻohana ʻana i nā ʻenehana kūikawā. Aia kekahi poʻe i loko o kēia lumi e hiki ke hōʻoia i kēia, ʻoiai ʻaʻole lākou i hoʻopaʻa ʻia e kahi ʻaelike huna. No laila, e hōʻike wau iā ʻoe pehea e hana ai. Hoʻopili kēia papahana i kekahi mau mea pāʻani. E ʻike ʻoe i ke ʻano o ka "pāʻani" pili hou.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Hoʻokomo ka pāʻani i kahi mea kālepa i loaʻa kekahi ʻano pūnaewele a huahana paha, a uku ʻo ia i nā komisina pili no nā kaomi mea hoʻohana, hana i nā moʻokāki, kūʻai ʻia, a pēlā aku. Uku ʻoe i kahi hui no kekahi e kipa i kā lākou pūnaewele, kaomi ma kahi loulou, e hele i kāu pūnaewele kalepa a kūʻai i kahi mea ma laila.

ʻO ka mea pāʻani aʻe he mea pili i loaʻa kālā ma ke ʻano o ka uku-kaomi (CPC) a i ʻole komisina (CPA) no ka hoʻohuli hou ʻana i nā mea kūʻai aku i ka pūnaewele o ka mea kūʻai aku.

Manaʻo nā Komisina ma muli o nā hana a ka hoa hana, ua kūʻai ka mea kūʻai aku ma ka pūnaewele o ka mea kūʻai aku.

ʻO ka mea kūʻai aku he kanaka nāna e kūʻai a kākau inoa paha i nā ʻāpana o ka mea kūʻai aku.

Hāʻawi nā pūnaewele pili i ka ʻenehana e hoʻopili a hahai i nā hana a ka mea kūʻai aku, hoa a me ka mea kūʻai aku. "Hoʻopili" lākou i nā mea pāʻani a pau a hōʻoia i kā lākou pilina.

Hiki iā ʻoe ke lawe i kekahi mau lā a i ʻole mau pule e hoʻomaopopo i ke ʻano o ka hana ʻana, akā ʻaʻohe ʻenehana paʻakikī ma aneʻi. Hoʻopili nā pūnaewele pili a me nā papahana pili i nā ʻano kālepa āpau a me nā mākeke āpau. Loaʻa iā Google, EBay, Amazon, ko lākou mau kuleana komisina, aia lākou ma nā wahi āpau a ʻaʻole nele i ka loaʻa kālā. Ua maopopo iaʻu ua ʻike ʻoe ʻo ke kaʻa mai kāu blog hiki ke lawe mai i mau haneli kālā i ka loaʻa kālā o kēlā me kēia mahina, no laila e maʻalahi kēia kumumanaʻo iā ʻoe e hoʻomaopopo.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻO kēia ke ʻano o ka ʻōnaehana. Hoʻopili ʻoe i kahi pūnaewele liʻiliʻi, a i ʻole kahi papa leka uila, ʻaʻole ia he mea nui, e kākau inoa no kahi papahana pili a loaʻa i kahi loulou kūikawā āu e kau ai ma kāu ʻaoʻao pūnaewele. Ua like me keia:

<a href=”http://AffiliateNetwork/p? program=50&affiliate_id=100/”>really cool product!</a>

Hoʻopili kēia i ka papahana pili kikoʻī, kāu ID pili, i kēia hihia he 100, a me ka inoa o ka huahana i kūʻai ʻia. A inā kaomi kekahi ma kēia loulou, kuhikuhi ka polokalamu kele pūnaewele iā ia i ka pūnaewele pili, hoʻonohonoho i nā kuki hoʻokele kūikawā e hoʻopili iā ia me ka ID pili=100.

Set-Cookie: AffiliateID=100

A kuhikuhi hou i ka ʻaoʻao o ka mea kūʻai aku. Inā kūʻai ka mea kūʻai mai i kekahi huahana i loko o ka manawa X, hiki ke lilo i lā, hoʻokahi hola, ʻekolu pule, i kēlā me kēia manawa i ʻae ʻia, a i kēia manawa e mau ana nā kuki, a laila e loaʻa i ka hoa kāna kōmike.

ʻO kēia ka papahana e loaʻa ai nā hui pili i nā piliona kālā me ka hoʻohana ʻana i nā loea SEO kūpono. E hāʻawi wau iā ʻoe i laʻana. Hōʻike ka paheʻe aʻe i ka māka, i kēia manawa e hoʻonui wau e hōʻike iā ʻoe i ka nui. He māka ia mai Google no $132. ʻO Schumann ka inoa o kēia keonimana, nona ka pūnaewele o nā pūnaewele hoʻolaha. ʻAʻole kēia ʻo ke kālā a pau, uku ʻo Google i kēlā mau kālā i hoʻokahi mahina a i hoʻokahi manawa i kēlā me kēia 2 mahina.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻO kahi hōʻoia hou mai Google, e hoʻonui au, a e ʻike ʻoe ua kākau ʻia no $901.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Pono au e nīnau i kekahi e pili ana i ke ʻano o kēia mau ʻano o ka loaʻa kālā? Hamau i loko o ke keʻena... Hōʻike kēia ʻeke i ka uku o 2 mahina no ka mea ua hōʻole ʻia ka ʻeke mua e ka panakō o ka mea loaʻa ma muli o ka nui o ka uku.

No laila, ke manaʻo nei mākou e hiki ke loaʻa ia mau kālā, a ua uku ʻia kēia kālā. Pehea e pāʻani ai i kēia papahana? Hiki iā mākou ke hoʻohana i kahi ʻenehana i kapa ʻia ʻo Cookie-Stuffing, a i ʻole Cookie Stuffing. He manaʻo maʻalahi loa kēia i ʻike ʻia ma 2001-2002, a hōʻike kēia paheʻe i ke ʻano o ka makahiki 2002. E haʻi aku wau iā ʻoe i ka moʻolelo o kona ʻano.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻAʻohe mea ʻē aʻe akā ʻo nā ʻōlelo lawelawe hoʻonāukiuki o nā ʻoihana pili e koi i ka mea hoʻohana e kaomi maoli i ka loulou i mea e hiki ai i kā lākou polokalamu kele ke kiʻi i ke kuki me ka ID pili.
Hiki iā ʻoe ke hoʻouka ʻokoʻa i kēia URL, i kaomi pinepine ʻia e ka mea hoʻohana, i loko o kahi kumu kiʻi a i ʻole i kahi hōʻailona iframe. A ma kahi o kahi loulou:

<a href=”http://AffiliateNetwork/p? program=50&affiliate_id=100/”>really cool product!</a>

Ke hoʻoiho nei ʻoe i kēia:

<img src=”http://AffiliateNetwork/p?program=50&affiliate_id=100/”>

A i ʻole:

<iframe src=”http://AffiliateNetwork/p?program=50&affiliate_id=100/”
width=”0” height=”0”></iframe>

A hiki ka mea hoʻohana i kāu ʻaoʻao, e ʻohi ʻakomi ʻo ia i ka kuki pili. I ka manawa like, me ka nānā ʻole inā kūʻai ʻo ia i kekahi mea i ka wā e hiki mai ana, e loaʻa iā ʻoe kāu komisina, inā ʻoe i hoʻihoʻi i ke kaʻa a ʻaʻole ʻole - ʻaʻole ia he mea nui.

I nā makahiki i hala iho nei, ua lilo kēia i mea leʻaleʻa no ka poʻe SEO e kau nei i nā mea e like me kēia ma nā papa leka a hoʻomohala i nā ʻano hiʻohiʻona āpau no kahi e waiho ai i kā lākou mau loulou. Ua ʻike nā hoa hakakā hiki iā lākou ke kau i kā lākou code ma nā wahi āpau ma ka Pūnaewele, ʻaʻole wale ma kā lākou mau pūnaewele ponoʻī.

Ma kēia paheʻe, hiki iā ʻoe ke ʻike i kā lākou mau polokalamu lako kuki ponoʻī e kōkua i nā mea hoʻohana e hana i kā lākou "kuki hoʻopiha". A ʻaʻole ia hoʻokahi kuki, hiki iā ʻoe ke hoʻoiho i 20-30 mau ID pūnaewele pili i ka manawa like, a ke kūʻai koke ʻia kekahi mea, e uku ʻia ʻoe no ia.

ʻAʻole i liʻuliʻu ua ʻike kēia poʻe ʻaʻole hiki iā lākou ke kau i kēia code ma kā lākou ʻaoʻao. Ua haʻalele lākou i ka kākau ʻana i ka pae ʻāina a hoʻomaka wale lākou e kau i kā lākou mau snippets liʻiliʻi me ka code HTML ma nā papa leka, ma nā puke malihini, ma nā ʻoihana pūnaewele.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Ma kahi o 2005, ʻike nā mea kūʻai aku a me nā ʻoihana pili i ka mea e hana nei, hoʻomaka ka ʻimi ʻana i nā mea kuhikuhi a kaomi i nā uku, a hoʻomaka i ke kīkē ʻana i nā mea pili. No ka laʻana, ʻike lākou ua kaomi ka mea hoʻohana ma kahi pūnaewele MySpace, akā aia kēlā pūnaewele i kahi pūnaewele pili ʻokoʻa loa ma mua o ka mea i loaʻa ka pōmaikaʻi kūpono.

Ua ʻoi aku ka naʻauao o kēia poʻe, a i ka makahiki 2007 ua hānau ʻia kahi ʻano Cookie-Stuffing hou. Hoʻomaka nā hoa e kau i kā lākou code ma nā ʻaoʻao SSL. Wahi a Hypertext Transfer Protocol RFC 2616, ʻaʻole pono nā mea kūʻai aku e hoʻokomo i kahi kahua poʻomanaʻo Referer i kahi noi HTTP insecure inā ua neʻe ka ʻaoʻao kuhikuhi mai kahi protocol palekana. ʻO kēia no ka mea ʻaʻole ʻoe makemake e hoʻokuʻu ʻia kēia ʻike mai kāu kikowaena.

Mai kēia mea i maopopo ʻaʻole hiki ke ʻike ʻia kahi Referer i hoʻouna ʻia i ka hoa, no laila e ʻike nā hoa nui i kahi loulou ʻole a ʻaʻole hiki iā lākou ke kipaku iā ʻoe. I kēia manawa ua loaʻa i nā scammers ka manawa e hana ai i kā lākou "kuki piha" me ka hoʻopaʻi ʻole. ʻOiaʻiʻo, ʻaʻole hiki i kēlā me kēia polokalamu ke ʻae iā ʻoe e hana i kēia, akā he nui nā ala ʻē aʻe e hana like ai, me ka hoʻohana ʻana i ka hoʻonui ʻana i ka ʻaoʻao o kēia manawa o ka polokalamu meta-refresh, meta tags a i ʻole JavaScript.

I ka makahiki 2008, hoʻomaka lākou e hoʻohana i nā mea hana hacking ikaika loa e like me ka hoʻouka hou ʻana - DNS rebinding, Gifar a me nā ʻike Flash maikaʻi ʻole e hiki ke hoʻopau loa i nā hiʻohiʻona pale. Loaʻa i kekahi manawa e noʻonoʻo ai pehea e hoʻohana ai iā lākou, no ka mea, ʻaʻole nā ​​​​kānaka Cookie Stuffing he poʻe hackers kiʻekiʻe loa, he mau mea kūʻai koʻikoʻi lākou ʻaʻole ʻike nui i ka coding.

Kūʻai aku i nā ʻike semi-loaʻa

No laila, ua nānā mākou pehea e loaʻa ai nā helu 6-helu, a i kēia manawa e neʻe mākou i nā helu ʻehiku. Pono mākou i ke kālā nui e waiwai ai a make paha. E nānā mākou pehea ʻoe e loaʻa ai ke kālā ma ke kūʻai ʻana i ka ʻike semi-loaʻa. Ua kaulana loa ʻo Business Wire i nā makahiki i hala aku nei a he mea nui ia, ʻike mākou ma nā pūnaewele he nui. No ka poʻe ʻike ʻole, hāʻawi ʻo Business Wire i kahi lawelawe kahi e loaʻa ai nā mea hoʻohana i hoʻopaʻa inoa ʻia o ka pūnaewele i kahi kahawai o nā hoʻolaha paʻi hou mai nā tausani o nā hui. Hoʻouna ʻia nā hoʻolaha paʻi i kēia hui e nā hui like ʻole i pāpā ʻia a hoʻopaʻa ʻia i kekahi manawa, no laila e pili ana ka ʻike i loko o kēia mau hoʻolaha i ka waiwai o nā ʻāpana.

Hoʻouka ʻia nā faila hoʻokuʻu paʻi i ka pūnaewele pūnaewele Business Wire akā ʻaʻole i hoʻopili ʻia a hiki i ka hoʻokuʻu ʻia ʻana o ka embargo. I nā manawa a pau, pili nā ʻaoʻao pūnaewele hoʻokuʻu i ka pūnaewele nui, a ʻike ʻia nā mea hoʻohana e pili ana iā lākou me nā URL e like me kēia:

http://website/press_release/08/29/2007/00001.html http://website/press_release/08/29/2007/00002.html http://website/press_release/08/29/2007/00003.htm

No laila, ʻoiai ʻoe ma lalo o ka embargo, kau ʻoe i nā ʻikepili hoihoi ma ka pūnaewele i ka wā i hāpai ʻia ai ka embargo, e hoʻomaʻamaʻa koke nā mea hoʻohana iā lākou iho. Hoʻouna ʻia kēia mau loulou i nā mea hoʻohana ma ka leka uila. I ka pau ʻana o ka pāpā, e hana ka loulou a kuhikuhi i ka mea hoʻohana i ka pūnaewele kahi i kau ʻia ai ka hoʻokuʻu paʻi pili. Ma mua o ka hāʻawi ʻana i ke komo ʻana i ka ʻaoʻao pūnaewele hoʻokuʻu paʻi, pono ka ʻōnaehana e hōʻoia i ka hoʻopaʻa ʻana o ka mea hoʻohana ma ke kānāwai.

ʻAʻole lākou e nānā inā loaʻa iā ʻoe ke kuleana e ʻike i kēia ʻike ma mua o ka pau ʻana o ka embargo, pono ʻoe e komo i ka ʻōnaehana. I kēia manawa, ʻaʻole ia he pōʻino, akā no ka hiki ʻole iā ʻoe ke ʻike i kekahi mea ʻaʻole ia he manaʻo ʻaʻole ia.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Ua ʻike ka ʻoihana kālā ʻo Estonian ʻo Lohmus Haavel & Viisemann, ʻaʻole ia he hacker, ua kapa ʻia nā ʻaoʻao pūnaewele hoʻokuʻu paʻi ma nā ʻano wānana a hoʻomaka e koho i kēlā mau URL. ʻOiai ʻaʻole hiki ke loaʻa nā loulou no ka mea ua paʻa ka embargo, ʻaʻole ia he manaʻo ʻaʻole hiki i ka mea hacker ke koho i ka inoa faila a no laila ke komo koke ʻia. Ua hana kēia ʻano hana no ka mea ʻo ka nānā palekana wale nō ʻo Business Wire ʻo ka mea hoʻohana i komo ma ke kānāwai, ʻaʻohe mea ʻē aʻe.

No laila, ua loaʻa iā Estonia ka ʻike ma mua o ka pani ʻana o ka mākeke a kūʻai aku i kēia ʻikepili. Ma mua o ka hahai ʻana o ka SEC iā lākou a hoʻopaʻa i kā lākou mau moʻokāki, ua loaʻa iā lākou he $ 8 miliona kālepa ʻike semi-loaʻa. E noʻonoʻo ua nānā wale kēia poʻe i ke ʻano o nā loulou, hoʻāʻo e koho i nā URL, a loaʻa iā 8 miliona mai ia mea. ʻO ka mea maʻamau i kēia manawa ke nīnau nei au i ka lehulehu inā manaʻo ʻia kēia i ke kānāwai a i ʻole ke kānāwai, inā pili ia i nā manaʻo o ke kālepa a ʻaʻole paha. Akā i kēia manawa, makemake wau e huki i kou manaʻo i ka mea nāna ia i hana.

Ma mua o kou hoʻāʻo ʻana e pane i kēia mau nīnau, e hōʻike wau iā ʻoe i ka slide hou. ʻAʻole pili kēia i nā scams pūnaewele. Ua hoʻopaʻa ʻia kahi hacker Ukrainian iā Thomson Financial, kahi mea hoʻolako i ka ʻike ʻoihana, a ʻaihue i ka pilikia kālā o IMS Health i nā hola ma mua o ka manaʻo e komo i ka mākeke kālā. ʻAʻohe mea kānalua ua hewa ʻo ia no ka ʻaihue.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Ua kauoha ka hacker e kūʻai aku i ka nui o 42 tausani kālā, e pāʻani ana a hiki i ka hāʻule ʻana o nā kumukūʻai. No Ukraine, he kālā nui kēia, no laila ua ʻike maopopo ka hacker i kāna mea e komo ai. ʻO ka hāʻule koke ʻana o ke kumukūʻai i loaʻa iā ia ma kahi o $300 i ka loaʻa kālā i loko o kekahi mau hola. Ua hoʻolaha ka hoʻololi ʻana i kahi Red Flag, ua hoʻokuʻu ka SEC i nā kālā, me ka ʻike ʻana ua hewa kekahi mea, a hoʻomaka i kahi hoʻokolokolo. Eia naʻe, ua ʻōlelo ʻo Judge Naomi Reis Buchwald e hoʻokuʻu ʻia nā kālā no ka mea ʻo Dorozhko i ʻōlelo ʻia "ʻaihue a kālepa" a me ka "hacking a me ke kālepa" ʻaʻole ia e uhaki i nā kānāwai palekana. ʻAʻole ʻo ka hacker he limahana o kēia hui, no laila ʻaʻole ʻo ia i uhaki i kekahi mau kānāwai e pili ana i ka hōʻike ʻana i ka ʻike pili kālā.

Ua manaʻo ka nūpepa ʻo Times e noʻonoʻo wale ke Keʻena ʻOihana ʻAmelika i kēia hihia he mea ʻole ma muli o nā pilikia e pili ana i ka loaʻa ʻana o ka ʻae o nā mana o Ukrainian e hui pū i ka hopu ʻana i ka mea lawehala. No laila ua maʻalahi kēia hacker i 300 tausani kālā.

E hoʻohālikelike i kēia me ka hihia ma mua kahi i loaʻa kālā ai nā kānaka ma ka hoʻololi ʻana i nā URL o nā loulou i kā lākou polokalamu kele pūnaewele a kūʻai aku i ka ʻike kalepa. He mea hoihoi loa kēia, akā ʻaʻole wale nā ​​ala e loaʻa kālā ai ma ke kūʻai kālā.

E noʻonoʻo i ka hōʻiliʻili ʻana i ka ʻike passive. ʻO ka mea maʻamau, ma hope o ka hana ʻana i kahi kūʻai pūnaewele, loaʻa ka mea kūʻai aku i kahi code tracking order, hiki ke sequential a pseudo-sequential a like me kēia:

3200411
3200412
3200413

Me ia, hiki iā ʻoe ke hahai i kāu kauoha. Ke ho'āʻo nei nā Pentesters a i ʻole nā ​​​​hacker e "scroll" i nā URL no ke komo ʻana i ka ʻikepili kauoha, maʻamau i loaʻa ka ʻike pilikino (PII):

http://foo/order_tracking?id=3200415
http://foo/order_tracking?id=3200416
http://foo/order_tracking?id=3200417

Ma ka ʻōwili ʻana i nā helu, loaʻa iā lākou ke komo i nā helu kāleka hōʻaiʻē, nā helu, nā inoa a me nā ʻike pilikino ʻē aʻe o ka mea kūʻai aku. Eia nō naʻe, ʻaʻole mākou makemake i ka ʻike pilikino o ka mea kūʻai aku, akā i ke code track order ponoʻī, makemake mākou i ka naʻauao passive.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻO ke akamai o ka unuhi ʻana i nā hopena

E noʻonoʻo i ke ʻano o ke kaha kiʻi ʻana. Inā hiki iā ʻoe ke hoʻohālikelike pololei i ka nui o nā "kauoha" e hana ʻia e kahi ʻoihana ma ka hopena o ka hapaha, a laila ma muli o ka ʻikepili mōʻaukala, hiki iā ʻoe ke hoʻoholo inā maikaʻi ke kūlana kālā a ma ke ala hea e loli ai kāna kumukūʻai. No ka laʻana, kauoha ʻoe a kūʻai paha i kekahi mea ma ka hoʻomaka ʻana o ka hapaha, ʻaʻole ia he mea nui, a laila hana i kahi kauoha hou ma ka hopena o ka hapaha. Ma ka ʻokoʻa o nā helu, hiki iā mākou ke hoʻoholo i ka nui o nā kauoha i hana ʻia e ka hui i kēia manawa. Inā mākou e kamaʻilio e pili ana i hoʻokahi kaukani kauoha me hoʻokahi haneli tausani no ka manawa like, hiki iā ʻoe ke manaʻo e hana maikaʻi ʻole ka ʻoihana.

Eia naʻe, ʻo ka mea ʻoiaʻiʻo, hiki ke loaʻa pinepine kēia mau helu helu me ka ʻole e hoʻokō maoli i kahi kauoha a i ʻole kahi kauoha i hoʻopau ʻia. Manaʻolana ʻaʻole e hōʻike ʻia kēlā mau helu a hoʻomau ke kaʻina me nā helu:

3200418
3200419
3200420

Ma kēia ala ʻike ʻoe he hiki iā ʻoe ke hahai i nā kauoha a hiki ke hoʻomaka i ka hōʻiliʻili ʻana i ka ʻike mai ka pūnaewele a lākou e hāʻawi mai ai iā mākou. ʻAʻole maopopo iā mākou inā he kānāwai a ʻaʻole paha, ʻike wale mākou hiki ke hana.

No laila, ua noʻonoʻo mākou i nā hemahema o ka loiloi ʻoihana.

Trey Ford: ʻO ka poʻe hoʻouka kaua he poʻe kālepa. Manaʻo lākou i ka hoʻihoʻi mai o kā lākou hoʻopukapuka. ʻOi aku ka ʻenehana, ʻoi aku ka nui a me ka paʻakikī o ke code, ʻoi aku ka nui o ka hana āu e pono ai e hana a ʻoi aku ka nui o ka hopu ʻia. Akā he nui nā ala maikaʻi loa e hoʻokō ai i nā hoʻouka me ka ʻole o ka hoʻoikaika ʻana. ʻO ka loiloi pāʻoihana he ʻoihana nui a aia kahi kumu hoʻoikaika nui no ka poʻe lawehala e uhaʻi. ʻO nā hemahema loina pāʻoihana kahi pahuhopu nui no nā lawehala a he mea hiki ʻole ke ʻike ʻia ma ka holo wale ʻana i kahi scan a i ʻole ka hana ʻana i ka hoʻāʻo QA maʻamau. Aia kekahi pilikia noʻonoʻo me ka hōʻoia maikaʻi ma QA, i kapa ʻia ʻo "confirmation bias" no ka mea, e like me nā mea ʻē aʻe, makemake mākou e ʻike ua pololei mākou. No laila, pono e hana i nā hoʻokolohua ma nā kūlana maoli.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

Pono e ho'āʻo i nā mea āpau a me nā mea āpau, no ka mea, ʻaʻole hiki ke loaʻa nā nāwaliwali āpau i ka pae hoʻomohala, ma ka nānā ʻana i ke code, a i ʻole i ka wā QA. No laila pono ʻoe e hele i ke kaʻina ʻoihana holoʻokoʻa a hoʻomohala i nā hana āpau e pale ai. Nui nā mea e hiki ke aʻo ʻia mai ka mōʻaukala no ka mea e hana hou ʻia kekahi mau ʻano hoʻouka i ka manawa. Inā ala ʻoe i hoʻokahi pō ma muli o ka hoʻohana ʻana i ka CPU kiʻekiʻe, a laila hiki iā ʻoe ke manaʻo e hoʻāʻo nei kekahi hacker e ʻimi hou i nā coupons hoʻemi kūpono. ʻO ke ala maoli e ʻike ai i ke ʻano o ka hoʻouka ʻana, ʻo ia ka nānā ʻana i kahi hoʻouka kaua, no ka mea, ʻo ka ʻike ʻana ma muli o ka mōʻaukala log he hana paʻakikī loa ia.

Jeremy Grossman: No laila, eia kā mākou i aʻo ai i kēia lā.

ʻaha kūkā ʻo BLACK HAT USA. Loaʻa i ka waiwai a i ʻole e make: ʻO ka loaʻa kālā ma ka pūnaewele me ka hoʻohana ʻana i nā ala ʻeleʻele. Mahele 3

ʻO ka hoʻoholo ʻana i nā captcha hiki ke loaʻa iā ʻoe nā helu ʻehā ma ke kālā. ʻO ka manipulations me nā ʻōnaehana uku pūnaewele e lawe mai i ka waiwai ʻelima mau helu i ka mea hacker. Hiki i nā panakō hacking ke loaʻa iā ʻoe ma mua o ʻelima mau helu, ʻoi aku inā ʻoi aku ʻoe ma mua o hoʻokahi.

E hāʻawi nā scams E-commerce iā ʻoe i ʻeono helu, a me ka hoʻohana ʻana i nā pūnaewele pili e hāʻawi iā ʻoe i nā helu 5-6 a i ʻole ʻehiku mau helu. Inā he wiwo ʻole ʻoe, hiki iā ʻoe ke hoʻāʻo e hoʻopunipuni i ka mākeke kūʻai a loaʻa ʻoi aku ma mua o ka waiwai ʻehiku. A ʻo ka hoʻohana ʻana i ke ʻano RSnake i nā hoʻokūkū no ka chihuahua maikaʻi loa he mea kūʻai ʻole!

ʻAʻole paha i hoʻokomo ʻia nā kiʻi paheʻe hou no kēia hōʻikeʻike ma ka CD, no laila hiki iā ʻoe ke hoʻoiho iā lākou ma hope mai kaʻu ʻaoʻao blog. Aia kahi hālāwai OPSEC e hiki mai ana i Sepatemaba e hele ai au, a manaʻo wau e hiki iā mākou ke hana i kekahi mau mea maikaʻi loa me lākou. A i kēia manawa, inā he nīnau kāu, ua mākaukau mākou e pane iā lākou.

Kekahi mau hoʻolaha 🙂

Mahalo no kou noho pū ʻana me mākou. Makemake ʻoe i kā mākou ʻatikala? Makemake ʻoe e ʻike i nā mea hoihoi hou aʻe? E kākoʻo iā mākou ma ke kau ʻana i kahi kauoha a i ʻole ka ʻōlelo ʻana i nā hoaaloha, cloud VPS no nā mea hoʻomohala mai $4.99, 30% ho'ēmi no nā mea hoʻohana Habr ma kahi kūʻokoʻa kūʻokoʻa o nā kikowaena helu komo, i hana ʻia e mākou no ʻoe: ʻO ka ʻoiaʻiʻo holoʻokoʻa e pili ana iā VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps mai $ 20 a pehea e kaʻana like ai i kahi kikowaena? (loaʻa me RAID1 a me RAID10, a hiki i 24 cores a hiki i 40GB DDR4).

ʻO Dell R730xd 2 mau manawa maʻalahi? Eia wale nō 2 x Intel TetraDeca-Core Xeon 2x E5-2697v3 2.6GHz 14C 64GB DDR4 4x960GB SSD 1Gbps 100 TV mai $199 ma Netherlands! Dell R420 - 2x E5-2430 2.2Ghz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB - mai $99! Heluhelu e pili ana Pehea e kūkulu ai i ka ʻoihana ʻoihana. papa me ka hoʻohana 'ana o Dell R730xd E5-2650 v4 kikowaena waiwai 9000 euros no ka peni?

Source: www.habr.com

Pākuʻi i ka manaʻo hoʻopuka