Methbot

pasdoy

Senior Member
Joined
Jul 17, 2008
Messages
910
Reaction score
327
http://go.whiteops.com/rs/179-SQE-823/images/WO_Methbot_Operation_WP.pdf

Have a read, it's very interesting. From another thread:
Normally a "real browser" can't run 100s of ad players at once, but "methbrowser" is a node.js application with a C module that speaks Flash's plugin protocol directly. It simulates a dom, runs JavaScript in a node VM, but doesn't have to do any of the messy rendering that things like PhantomJS have to.

It was discovered years ago because:

* Their IP stack was acting like Linux[1]

* Their flash player said "I'm Linux"

* Their user agent said other things (random user agents)

* Their DNS traffic was going UK, but the hosts were coming out of the US
 
This is real interesting stuff. A node.js headless monster.
 
$3,000,000 a day?wut.

Will have to read this completely later.
 
Yes i read about this on CNN.... I was actually looking for something like this for long time ago..
 
Now that's some blackhat shit!

Update: The methbot was using the same nickname "adw0rd" which was listed in the phony ISP internet address ranges. After further research adw0rd is connected to the same developer on https://github.com/adw0rd as well as many other sites like forums, fb, twitter etc.

Looks like this dude didn't cover his tracks good enough!
 
Last edited:
why not? have you checked the spec and what they do?
 
yeah I guess its better keep it small. get to a steady 3k/week.
 
Back
Top