1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Stealing Adsense Accounts

Discussion in 'Black Hat SEO' started by kojakfull, Mar 18, 2008.

  1. kojakfull

    kojakfull Senior Member

    Joined:
    Jan 13, 2008
    Messages:
    851
    Likes Received:
    1,050
    Location:
    CustomBotSolutions.com
    Home Page:
    Ok guys i just get this from another private blackhat forum and wanted to share it here. I didnt try this yet coz i dont know how it works maybe someone can get this working.

    here it is:

    ******************************************

    Ok guys this is real Heavy Blackhat!!!!!!
    Do not try this at Home or at all / or ONLY ON YOUR OWN ACCOUNT
    EDUCATIONAL PURPASES ONLY!!!!!!!!

    This is a kind of CSRF hackish something. Normally I don't do a lot of CSRF but this time I could not resist to try it on myself. It works very simple. I hava a page on my server which writes the email and password change URI from your Google adsense account. Into that URI I just paste my emailadres and my password. If you open this file and you are logged into Adsense inside another Firefox tab or MSIE screen, I will reset your login credentials to my own and stealing all your money. -great isn't it, tabbed browsing?- *grin*

    I'm amazed it's just that easy to do, with the help of bad cookie based authentication.

    Granted, the owner will get an email, but he doesn't have to do anything. it's changed by default when it happens. If it doesn't work out, we can also try to change the password alone.
     
  2. vmedia

    vmedia Regular Member

    Joined:
    Feb 6, 2008
    Messages:
    239
    Likes Received:
    28
    i don't think you'd get away with it for long though....
     
  3. MR.blackhat

    MR.blackhat Regular Member

    Joined:
    Nov 4, 2007
    Messages:
    270
    Likes Received:
    46
    Occupation:
    Black Hat Marketer
    Location:
    USA
    very BH......WOW.....

    i think i know a couple of sites to try this on but i will not cuz its very extreme
     
  4. fxmaster

    fxmaster Regular Member

    Joined:
    Dec 20, 2007
    Messages:
    219
    Likes Received:
    477
    You stole this from blackhatters didn't you?
     
  5. j21primetime

    j21primetime Junior Member

    Joined:
    Mar 7, 2008
    Messages:
    126
    Likes Received:
    29
    Occupation:
    Male Escort
    Location:
    Right Behind You
    I bet this is happening on clickbank already!!
     
  6. blackmark

    blackmark Registered Member

    Joined:
    Mar 7, 2008
    Messages:
    55
    Likes Received:
    8
    ok so make sure that everytime you open your adsense account don't forget to logout
     
  7. rubixcubeman

    rubixcubeman Registered Member

    Joined:
    Feb 13, 2008
    Messages:
    74
    Likes Received:
    14
    Occupation:
    Vagabond
    Location:
    Canada
    I'm glad someone created NoScript so I don't find this kind of thing affecting me. Its a very wicked exploit though, wow.
     
  8. Uptownbulker

    Uptownbulker BANNED BANNED

    Joined:
    Oct 21, 2007
    Messages:
    960
    Likes Received:
    477
    Well, how reliable can this be anyway; dumb bastard can't even spell: "PURPASES"(sic)!

    This is precisely the kind of ignorant shit which gets sites in trouble.

    "Stealing" accounts.

    Great.

    Fuckhead.
     
  9. Dragn

    Dragn Regular Member

    Joined:
    Mar 5, 2008
    Messages:
    329
    Likes Received:
    83
    im all for bending rules until they break, but there is one HUGE flaw in this:

    before you even see a single payment, 10 bucks says google adsense is notified by the person you stole from and you never see a dime, and possibly get banned from your own stuff google related.
     
  10. vmedia

    vmedia Regular Member

    Joined:
    Feb 6, 2008
    Messages:
    239
    Likes Received:
    28
    not to mention what the google lawyers would do if you ever cashed their checks...
     
  11. KeijoKala

    KeijoKala Jr. VIP Jr. VIP Premium Member

    Joined:
    Jan 16, 2008
    Messages:
    568
    Likes Received:
    120
    Its hard to change payeer name in adsense.... so there is nothing to do with this...
     
  12. Zak_A

    Zak_A Jr. VIP Jr. VIP Premium Member

    Joined:
    Mar 16, 2008
    Messages:
    808
    Likes Received:
    873
    Gender:
    Male
    Occupation:
    WP designer & developer
    Location:
    Western Europe
    I tried the code, it doesn't seem to work :
    I have two adsense accounts (the payee's name of the first one is a friend of mine because I wasn't 18 when I created it :D )
    So I logged into it and tried to put use this url (to get the money in my second account :p ) :
    Code:
    https://www.google.com/accounts/UpdateEmail?service=adsense&Email=mymail@mymail.com&Passwd=mypassword&save=
    And an adsense error loaded saying "There's is already an user registered with mymail@mymail.com"
    Then I tried it with an other email adresse that is not registered to adsense, and I got an other error : "Please login or sign up"

    ...:rolleyes:
     
  13. Metalwarrior

    Metalwarrior Newbie

    Joined:
    Feb 2, 2008
    Messages:
    32
    Likes Received:
    3
    A ticket to go straight to hell :p
    It's hard to steal people's adsense money :p They can just report it. lol.
     
  14. fxmaster

    fxmaster Regular Member

    Joined:
    Dec 20, 2007
    Messages:
    219
    Likes Received:
    477
    Trust me they is no way of changing the name i requested google change my name seeming as i was using some 1 elses name, and guess what? they banned me :p