Hide your hop link

bass.bandito

Regular Member
Joined
Apr 3, 2010
Messages
265
Reaction score
68
This is the method that "Mark" from www.forex-tester.com makes his money with when he reviews the products. It hides if refferal link but when you click buy it shows at the bottom he is refferal. IDK how to use it so really im asking for help. However he isnt to smart for making this "viewable"

HTML:
<body bgcolor="#FFFFFF" text="#000000">
<script>function cloakst1(){window.status="Opening Page http://aeroninfo.com";} zint=setInterval(cloakst1,10)</script>
<Script Language='Javascript'>s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";eval(unescape("%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B"));</script><noscript>This Page requires a JavaScript-enabled browser.</noscript>

please help me understand how to use this.
 
That long string looks like an encoded something or other... the domain name is prolly a redirect which has a JS file on it to decode the s= ..... but I couldn't tell you because I don't speak JS.
 
That long string looks like an encoded something or other... the domain name is prolly a redirect which has a JS file on it to decode the s= ..... but I couldn't tell you because I don't speak JS.

I downloaded a few JS' with a site template ripper. Very interesting... I think he might have did the JS version of JAVA obfuscation. lol.

Edit: I got this out of a encoder/decoder:
Code:
(t="";for(i=0;i<c.length;i++){if(i%2==0)t+="%";t+=c.charAt(i);}eval(unescape(t));t="";

from

Code:
%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B

edit 2:
This is all i could decrypt:
Code:
<Script Language='Javascript'>s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";eval(unescape("t="";for(i=0;i<c.length;i++){if(i%2==0)t+="%";t+=c.charAt(i);}eval(unescape(t));t="";"));</script>
 
Last edited:
thanks this is awesome!

not really. I don't know what the hell the two REALLY number sequences are. I ned a java scripter to help.


Here is what you need to type in google to see what im decrypting:
Code:
view-source:http://forex-tester.com/aeron.html
 
Can a mod move this to the clink bank section?
 
can someone please explain what this guy is doing?
I've been looking to do something like this, but everywhere I ask or read, people tell me to use PHP and to do

Code:
<?php

   header( 'Location: http:/.xxxx.com' ) ;

?>

But I know this is just a 301 redirect. How can I do the same as this guy? Everywhere I google I just run into some marketers trying to sell me a cloaking script...

need real answers!!
 
can someone please explain what this guy is doing?
I've been looking to do something like this, but everywhere I ask or read, people tell me to use PHP and to do

Code:
<?php

   header( 'Location: http:/.xxxx.com' ) ;

?>

But I know this is just a 301 redirect. How can I do the same as this guy? Everywhere I google I just run into some marketers trying to sell me a cloaking script...

need real answers!!
lol? Selling cloaking scripts? Well, i'm with you... i wanna know how this fatass cloaks his redirects using js. I just wanna be able to take out my hoplink at the end like him.
 
so could anyone please help us out with some insightful information? plz...!
 
Might be able to help ya out with this one I'm thinking that he is just converting the url to an ip address and then turning it into a dword.... http://www.pc-help.org/obscure.htm check out this link should give you a good run at what you are looking at :D
 
might be able to help ya out with this one i'm thinking that he is just converting the url to an ip address and then turning it into a dword.... http://www.pc-help.org/obscure.htm check out this link should give you a good run at what you are looking at :d

oh shit hahahahahaha very nice man thanks! Wait though, how do you "de obscure" it? If im saying that right :|
 
Last edited:
wow the guy who made this is a real smart ass prick. I've been trying to pull it apart for the past hour and i'm still confused lol
 
beautiful script :)

anyway i decoded it. here goes:

we start with the original code
Code:
<body bgcolor="#FFFFFF" text="#000000">
<script>function cloakst1(){window.status="Opening Page  http://aeroninfo.com";} zint=setInterval(cloakst1,10)</script>
<Script  Language='Javascript'>s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";eval(unescape("%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B"));</script><noscript>This  Page requires a JavaScript-enabled browser.</noscript>
add some line breaks to make it easier to read

Code:
<body bgcolor="#FFFFFF" text="#000000">

<script>
function cloakst1(){
window.status="Opening Page http://aeroninfo.com";
} 

zint=setInterval(cloakst1,10)
</script>

<Script Language='Javascript'>

s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";

c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";

eval(unescape("%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B"));

</script>

<noscript>
This Page requires a JavaScript-enabled browser.
</noscript>
the status bar text is cloaked to display a custom message every 10 ms.
2 variables "s" and "c" are set to strings, and the eval function is called.

we use this site: http://www.tareeinternet.com/scripts/unescape.html
to decode the function to this:

Code:
t="";

for(i=0;i<c.length;i++)
{
    if(i%2==0)
        t+="%";

    t+=c.charAt(i);
}

eval(unescape(t));

t="";
which basically takes the "c" variable and inserts a % symbol between every 2 characters

Code:
c="%74%32%3D%22%22%3B%66%6F%72%28%69%32%3D%30%3B%69%32%3C%73%2E%6C%65%6E%67%74%68%3B%69%32%2B%2B%29%7B%69%66%28%69%32%25%33%3D%3D%30%29%74%32%2B%3D%22%25%22%3B%65%6C%73%65%20%74%32%2B%3D%73%2E%63%68%61%72%41%74%28%69%32%29%3B%7D%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%32%29%29%3B%74%32%3D%22%22%3B";
and then runs the eval function on it. using that same site again to decode the function, we get

Code:
t2="";

for(i2=0;i2<s.length;i2++)
{
    if(i2%3==0)
        t2+="%";
    else 
        t2+=s.charAt(i2);
}

document.write(unescape(t2));

t2="";
which does something similar as before, except this time we take every 3rd character in the "s" variable and replace it with a % symbol

Code:
s="%3C%65%6D%62%65%64%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%35%37%3B%26%23%35%35%3B%26%23%31%30%31%3B%26%23%34%39%3B%26%23%31%30%32%3B%26%23%35%32%3B%26%23%35%37%3B%26%23%31%31%32%3B%26%23%31%31%38%3B%26%23%31%30%33%3B%26%23%35%30%3B%26%23%31%31%32%3B%26%23%31%30%32%3B%26%23%31%31%39%3B%26%23%35%31%3B%26%23%34%39%3B%26%23%31%30%33%3B%26%23%31%30%39%3B%26%23%31%31%38%3B%26%23%31%30%34%3B%26%23%31%32%31%3B%26%23%31%30%35%3B%26%23%31%30%37%3B%26%23%31%31%32%3B%26%23%34%39%3B%26%23%31%31%35%3B%26%23%34%36%3B%26%23%31%30%34%3B%26%23%31%31%31%3B%26%23%31%31%32%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%30%38%3B%26%23%31%30%35%3B%26%23%39%39%3B%26%23%31%30%37%3B%26%23%39%38%3B%26%23%39%37%3B%26%23%31%31%30%3B%26%23%31%30%37%3B%26%23%34%36%3B%26%23%31%31%30%3B%26%23%31%30%31%3B%26%23%31%31%36%3B%26%23%34%37%3B%22%20%77%69%64%74%68%3D%22%32%22%20%68%65%69%67%68%74%3D%22%32%22%3E%3C%2F%65%6D%62%65%64%3E%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%3D%22%52%65%66%72%65%73%68%22%20%63%6F%6E%74%65%6E%74%3D%22%30%3B%75%72%6C%3D%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%31%30%31%3B%26%23%31%31%34%3B%26%23%31%31%31%3B%26%23%31%31%30%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%32%3B%26%23%31%31%31%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%22%3E";
then run it through the same decoder and we get some plaintext html tags along with a different type of html escape character encoding (which i had to replace it with -------- because bhw automatically decodes it.)

Code:
<embed src="-------------" width="2" height="2">
</embed>

<meta http-equiv="Refresh" content="0;url=-----------------">
copy out the sections in the -------- and paste it into a blank .html file to decode them.

it comes out to

Code:
<embed src="http://97e1f49pvg2pfw31gmvhyikp1s.hop.clickbank.net/" width="2" height="2">
</embed>

<meta http-equiv="Refresh" content="0;url=http://aeroninfo.com">
and this apparently cookie stuffs the visitor before redirecting them to the non-affiliate url, so that their affiliate id doesn't show up in the address bar. (although this method isn't very reliable and he's probably losing a lot of sales right here)

so, we just paste the encrypted hoplink into a browser and arrive at the plain, unencrypted affiliate link

Code:
http://www.aeroninfo.com/?hop=fxrrt
hello, fxrrt

overall, very linear. now if he had implemented some recursion in there... that might have been tough to crack :)

i love this shit :D


EDIT: so, if you wanted to use this for yourself, you'd just have to do all these steps backwards haha
imo its really kinda pointless to do THIS MUCH encoding since, like the op said, after clicking through to the order form you'll see the affiliate id anyway.
lol
 
Last edited:
So question here is: why on earth anyone would go through all this trouble when you can just do a php header() function and do a 301 redirect to the offer? Especially when you have a totally legit site that reviews forex products?

Edit: Nevermind. To anyone wondering the same thing, it appears to the user that he's not on a reflink, it kinda "stuffs" the cookie before doing the redirect to a main page.

Other uses for this: sending people to -any- landing page of a clickbank site
 
Last edited:
beautiful script :)

anyway i decoded it. here goes:

we start with the original code
Code:
<body bgcolor="#FFFFFF" text="#000000">
<script>function cloakst1(){window.status="Opening Page  http://aeroninfo.com";} zint=setInterval(cloakst1,10)</script>
<Script  Language='Javascript'>s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";eval(unescape("%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B"));</script><noscript>This  Page requires a JavaScript-enabled browser.</noscript>
add some line breaks to make it easier to read

Code:
<body bgcolor="#FFFFFF" text="#000000">

<script>
function cloakst1(){
window.status="Opening Page http://aeroninfo.com";
} 

zint=setInterval(cloakst1,10)
</script>

<Script Language='Javascript'>

s="E3CD65E6DC62C65F64A20F73F72E63A3DC22G26F23C31G30G34A3BG26C23D31F31A36E3BD26C23E31E31B36B3BF26F23E31G31G32B3BE26G23B35D38A3BG26E23A34E37A3BA26F23B34A37C3BC26C23G35G37C3BB26B23B35E35C3BC26E23C31E30B31B3BE26A23D34G39B3BF26C23C31G30E32E3BC26A23D35E32G3BF26A23D35G37D3BE26D23D31D31C32C3BB26A23B31G31A38C3BC26D23B31D30B33E3BD26B23G35E30D3BC26A23F31D31F32E3BF26A23B31A30A32C3BA26A23D31E31D39F3BA26B23E35D31C3BB26E23G34D39A3BF26C23D31D30B33C3BA26E23B31G30A39D3BB26G23F31B31E38B3BA26A23C31F30C34B3BD26B23C31A32D31B3BG26E23F31G30C35D3BA26E23C31G30A37G3BE26C23B31D31B32G3BA26A23C34D39G3BD26C23F31F31E35F3BG26C23D34C36E3BB26C23D31F30D34C3BD26B23E31D31E31G3BC26C23C31B31D32B3BE26C23G34D36B3BE26F23E39F39B3BF26B23G31A30A38F3BC26D23A31A30B35A3BF26D23D39B39D3BF26F23C31G30F37A3BE26E23A39D38C3BB26G23F39E37C3BF26B23C31D31G30A3BE26C23A31B30A37D3BG26D23D34G36B3BC26C23B31D31A30D3BG26D23G31E30D31E3BA26F23E31D31B36B3BC26F23A34D37F3BF22C20G77F69E64G74G68C3DA22G32F22E20C68A65B69B67D68C74A3DB22E32F22D3EB3CG2FC65C6DF62B65D64B3EG3CE6DC65C74G61E20G68D74C74G70B2DB65B71C75A69F76F3DB22E52C65F66F72D65A73C68C22E20C63F6FB6EE74G65B6EG74A3DG22E30E3BG75E72B6CG3DA26D23F31B30C34C3BD26B23E31B31A36G3BA26E23G31B31G36F3BD26D23F31F31C32B3BC26C23B35E38A3BB26E23D34B37G3BD26A23C34C37F3BG26F23B39A37A3BB26C23B31G30G31E3BF26B23B31A31F34F3BF26C23D31D31F31D3BB26B23C31E31C30D3BC26E23A31D30B35G3BG26G23F31C31F30G3BB26B23E31A30C32E3BA26A23C31C31D31C3BC26F23C34C36C3BF26C23F39E39C3BG26E23D31B31E31F3BD26G23B31E30G39B3BC22A3E";

c="74323D22223B666F722869323D303B69323C732E6C656E6774683B69322B2B297B696628693225333D3D302974322B3D2225223B656C73652074322B3D732E636861724174286932293B7D646F63756D656E742E777269746528756E65736361706528743229293B74323D22223B";

eval(unescape("%74%3D%22%22%3B%66%6F%72%28%69%3D%30%3B%69%3C%63%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%69%66%28%69%25%32%3D%3D%30%29%74%2B%3D%22%25%22%3B%74%2B%3D%63%2E%63%68%61%72%41%74%28%69%29%3B%7D%65%76%61%6C%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%74%3D%22%22%3B"));

</script>

<noscript>
This Page requires a JavaScript-enabled browser.
</noscript>
the status bar text is cloaked to display a custom message every 10 ms.
2 variables "s" and "c" are set to strings, and the eval function is called.

we use this site: http://www.tareeinternet.com/scripts/unescape.html
to decode the function to this:

Code:
t="";

for(i=0;i<c.length;i++)
{
    if(i%2==0)
        t+="%";

    t+=c.charAt(i);
}

eval(unescape(t));

t="";
which basically takes the "c" variable and inserts a % symbol between every 2 characters

Code:
c="%74%32%3D%22%22%3B%66%6F%72%28%69%32%3D%30%3B%69%32%3C%73%2E%6C%65%6E%67%74%68%3B%69%32%2B%2B%29%7B%69%66%28%69%32%25%33%3D%3D%30%29%74%32%2B%3D%22%25%22%3B%65%6C%73%65%20%74%32%2B%3D%73%2E%63%68%61%72%41%74%28%69%32%29%3B%7D%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%32%29%29%3B%74%32%3D%22%22%3B";
and then runs the eval function on it. using that same site again to decode the function, we get

Code:
t2="";

for(i2=0;i2<s.length;i2++)
{
    if(i2%3==0)
        t2+="%";
    else 
        t2+=s.charAt(i2);
}

document.write(unescape(t2));

t2="";
which does something similar as before, except this time we take every 3rd character in the "s" variable and replace it with a % symbol

Code:
s="%3C%65%6D%62%65%64%20%73%72%63%3D%22%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%35%37%3B%26%23%35%35%3B%26%23%31%30%31%3B%26%23%34%39%3B%26%23%31%30%32%3B%26%23%35%32%3B%26%23%35%37%3B%26%23%31%31%32%3B%26%23%31%31%38%3B%26%23%31%30%33%3B%26%23%35%30%3B%26%23%31%31%32%3B%26%23%31%30%32%3B%26%23%31%31%39%3B%26%23%35%31%3B%26%23%34%39%3B%26%23%31%30%33%3B%26%23%31%30%39%3B%26%23%31%31%38%3B%26%23%31%30%34%3B%26%23%31%32%31%3B%26%23%31%30%35%3B%26%23%31%30%37%3B%26%23%31%31%32%3B%26%23%34%39%3B%26%23%31%31%35%3B%26%23%34%36%3B%26%23%31%30%34%3B%26%23%31%31%31%3B%26%23%31%31%32%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%30%38%3B%26%23%31%30%35%3B%26%23%39%39%3B%26%23%31%30%37%3B%26%23%39%38%3B%26%23%39%37%3B%26%23%31%31%30%3B%26%23%31%30%37%3B%26%23%34%36%3B%26%23%31%31%30%3B%26%23%31%30%31%3B%26%23%31%31%36%3B%26%23%34%37%3B%22%20%77%69%64%74%68%3D%22%32%22%20%68%65%69%67%68%74%3D%22%32%22%3E%3C%2F%65%6D%62%65%64%3E%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%3D%22%52%65%66%72%65%73%68%22%20%63%6F%6E%74%65%6E%74%3D%22%30%3B%75%72%6C%3D%26%23%31%30%34%3B%26%23%31%31%36%3B%26%23%31%31%36%3B%26%23%31%31%32%3B%26%23%35%38%3B%26%23%34%37%3B%26%23%34%37%3B%26%23%39%37%3B%26%23%31%30%31%3B%26%23%31%31%34%3B%26%23%31%31%31%3B%26%23%31%31%30%3B%26%23%31%30%35%3B%26%23%31%31%30%3B%26%23%31%30%32%3B%26%23%31%31%31%3B%26%23%34%36%3B%26%23%39%39%3B%26%23%31%31%31%3B%26%23%31%30%39%3B%22%3E";
then run it through the same decoder and we get some plaintext html tags along with a different type of html escape character encoding (which i had to replace it with -------- because bhw automatically decodes it.)

Code:
<embed src="-------------" width="2" height="2">
</embed>

<meta http-equiv="Refresh" content="0;url=-----------------">
copy out the sections in the -------- and paste it into a blank .html file to decode them.

it comes out to

Code:
<embed src="http://97e1f49pvg2pfw31gmvhyikp1s.hop.clickbank.net/" width="2" height="2">
</embed>

<meta http-equiv="Refresh" content="0;url=http://aeroninfo.com">
and this apparently cookie stuffs the visitor before redirecting them to the non-affiliate url, so that their affiliate id doesn't show up in the address bar. (although this method isn't very reliable and he's probably losing a lot of sales right here)

so, we just paste the encrypted hoplink into a browser and arrive at the plain, unencrypted affiliate link

Code:
http://www.aeroninfo.com/?hop=fxrrt
hello, fxrrt

overall, very linear. now if he had implemented some recursion in there... that might have been tough to crack :)

i love this shit :D


EDIT: so, if you wanted to use this for yourself, you'd just have to do all these steps backwards haha
imo its really kinda pointless to do THIS MUCH encoding since, like the op said, after clicking through to the order form you'll see the affiliate id anyway.
lol

I <3 you. MANY THANKS.
 
Back
Top