shadysterra
Newbie
- Apr 19, 2025
- 1
- 2
They inject heavily obfuscated JS code to your webpage even when you place a seemingly simple banner. It filters users and selectively redirect some people out of your website. This happens more common to mobile browsers.
It happens in ad platforms but the fact that they made it so difficult to debug and detect, they hid the injection to a plain banner (not social banner or anything) all points that their business is shady.
Apologies if this is already well-known fact and a common practice, I just experienced it anew. The fact they don't don't have delete account button, you have to contact their "super-fast" customer service to beg to delete the account.
Here is a summary of the code they injected to my website (from a simple banner).
1. Redirection - Full page redirect on back button or cookie absence
2. Hidden iframe loading - Loads tracking ads invisibly
3. Fingerprinting user/device - Very aggressive fingerprinting
4. Developer Tools detection - Can block or modify behavior
5. Hidden tracking requests (XHR) - Silent tracking without user consent
6. Anti-debugging loops - Blocks debuggers from analyzing it
7. Forced cookies - Sets tracking cookies
8. Multiple tracking domains - Fallback in case domains are blacklisted
It happens in ad platforms but the fact that they made it so difficult to debug and detect, they hid the injection to a plain banner (not social banner or anything) all points that their business is shady.
Apologies if this is already well-known fact and a common practice, I just experienced it anew. The fact they don't don't have delete account button, you have to contact their "super-fast" customer service to beg to delete the account.
Here is a summary of the code they injected to my website (from a simple banner).
1. Redirection - Full page redirect on back button or cookie absence
2. Hidden iframe loading - Loads tracking ads invisibly
3. Fingerprinting user/device - Very aggressive fingerprinting
4. Developer Tools detection - Can block or modify behavior
5. Hidden tracking requests (XHR) - Silent tracking without user consent
6. Anti-debugging loops - Blocks debuggers from analyzing it
7. Forced cookies - Sets tracking cookies
8. Multiple tracking domains - Fallback in case domains are blacklisted