1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

How are they tracking me?

Discussion in 'BlackHat Lounge' started by tixpf, Feb 14, 2014.

  1. tixpf

    tixpf Regular Member

    Joined:
    Dec 1, 2013
    Messages:
    295
    Likes Received:
    114
    This may be a noob question, but I'm absolutely stumped. I have no idea how the hell facebook/google know my location. I've tried to register a couple of fake facebook accounts for a campaign I'm about to launch (1st time ever I'm using FB accounts for traffic), but I simply can't get a single account to pass the fake check. Every single time they ask me to verify my identity with a mobile phone number and I'm obviously not going to do that.

    What's strange is even though I completely wiped everything (CCLeaner), I'm not using Chrome, used an US VPN (free one, vpnbook), disabled JavaScript, changed the firefox standard language from my language to english and still once I go to facebook.com the website appears in my language.
    This is seriously driving me nuts. Is there anything I am missing? Is there sort of a guide on how to create fake accs? Because it can't be that hard, since almost every noob guide suggests to create one for promotion purposes.

    Any help is highly appreciated.
     
  2. WorkHardL0veLife

    WorkHardL0veLife Regular Member

    Joined:
    Mar 14, 2011
    Messages:
    219
    Likes Received:
    423
    That could be the issue. Maybe you need better proxies
     
  3. ChangGun

    ChangGun Newbie

    Joined:
    Feb 7, 2010
    Messages:
    35
    Likes Received:
    6
    lol.

    OK. Two things

    1. VPN is detectable in most cases, especially the free ones. SOCKS5 layer is always better for location spoofing.

    2. A lot of organizations now use your computer's MAC address to identify your computer. If your MAC address and Computer Name and Windows USER matches something that they have on record, they will return the last settings used by that computer.


    - My 2 cents
     
  4. Snckr

    Snckr BANNED BANNED

    Joined:
    Dec 27, 2013
    Messages:
    582
    Likes Received:
    381
    Don't use a free VPN, get virgin private proxies (request from provider).
     
  5. tixpf

    tixpf Regular Member

    Joined:
    Dec 1, 2013
    Messages:
    295
    Likes Received:
    114
    Ok makes sense.
    So I get that there's more that needs to be done to create a fake profile, but I can't be the only one ever who has encountered that problem and needs assistance creating a new profile. How do you guys do it?

    @ChangGun
    1. I was almost sure that VPN wasn't enough so that doesn't surprise me
    2. Shouldn't I be able to solve the MAC/computer name problem by using a virtual machine?
     
  6. akacash

    akacash Jr. VIP Jr. VIP

    Joined:
    Jan 16, 2010
    Messages:
    807
    Likes Received:
    576
    Location:
    The Beach, USA
    Just recommended this to someone else last night. Make sure you're computer date and time zone settings match that of your VPN, or private proxy. Disabling js was already mentioned so you should be good there.
     
  7. tixpf

    tixpf Regular Member

    Joined:
    Dec 1, 2013
    Messages:
    295
    Likes Received:
    114
    So even with a free VPN this what you suggested + disabled JS should do the trick?
     
  8. ChangGun

    ChangGun Newbie

    Joined:
    Feb 7, 2010
    Messages:
    35
    Likes Received:
    6
    No . MAC is determined by the network cards on your machine (Ethernet, wireless , etc)

    There are software like S-MAC and T-MAC that you can use to spoof your MAC address.
     
  9. akacash

    akacash Jr. VIP Jr. VIP

    Joined:
    Jan 16, 2010
    Messages:
    807
    Likes Received:
    576
    Location:
    The Beach, USA
    Oh I'm not saying it will work 100% at all, but it's 2 more things that you hadn't listed that I would personally do myself. One thing I thought was already mentioned, but I not see is not, is to make sure you're clearing out your flash cookies as well. Some sites will store a flash cookie that will not be deleted by using your browser to clear cookies. I'm don't think there's even any program out that does it, although I'm sure there has to be somewhere, but you need to go do it manually. Typically they're in your temp folder inside of the hidden AppData folder.

    In no way though am I saying this will work 100%, however it will absolutely increase your chances of fixing it, if not fixing it altogether. Good luck and have a great day :)
     
  10. tixpf

    tixpf Regular Member

    Joined:
    Dec 1, 2013
    Messages:
    295
    Likes Received:
    114
    I did it.. holy mother. I didn't expect this to be that complicated.

    Just in case anyone's planning to create fake FB profies in the future, here's a method that worked for me:

    • spoof your MAC address
    • use a VPN (vpnbook worked for me)
    • change the timezone of your computer
    • wipe all cookies/temp data/etc. (CCLeaner is fine)
    • disable JavaScript in your browser



    So now that I've got a fake account created, how exactly do I have to handle it?
    1. Do I have to wipe all cookies/temp date/.. and only then log into the account?
    2. Do I have to spoof my MAC every single time I log into the account?

    I'm pretty sure the VPN is mandatory for the log in so I didn't list it.