Example Cookie-Stuffing Overwriting Existing Cookies: FogDog
The Effect of 180solutions on Affiliate Commissions and Merchants - Ben Edelman

As discussed in Affiliate Code Replacement via Popup "Double" Windows within The Effect of 180solutions on Affiliate Commissions and Merchants, 180 has implemented a system that can set affiliate tracking codes by showing a user a duplicate copy of a merchant's site. These popups set affiliate codes that, in the ordinary course of events, cause 180 to be paid commissions otherwise payable to other affiliates, and cause 180 to be paid commissions even if no commissions would otherwise be paid. For a listing of affected merchants (as of tests of June 2004), see merchants targeted with double windows. See also merchants I previously found to be targeted with silent cookie-stuffing.

This page shows specific network transmissions that implement 180's double-popup cookie-stuffing, targeting a request for fogdog.com made at approximately 10pm (Eastern) on July 23, 2004. See also a video (WMV format, view in full-screen mode) confirming what took place, including showing my Cookies folder before and after receiving the 180solutions popup. The thumbnail at right shows the final on-screen display -- the fogdog.com site, covered in part by the double popup that reached fogdog.com through an affiliate link.

Index of Annotated Packet Logs (details)

Other Targeted Merchants: Double and Silent Popups

In this example, I sought to document how 180 (and its advertisers) can overwrite cookies set by other affiliates. My testing proceeded in the following way:

  1. I cleared my cookies, such that any cookies set on my PC were set in the course of the testing shown in my video.
  2. I browsed to cash-us.com, an ordinary affiliate site that links to fogdog.com via an affiliate link. I clicked through that affiliate link, yielding the sequence of HTTP communications shown in HTTP Transaction 1 (with original affiliate link shown in red highlighting, and resulting cookies in blue highlighting).
  3. I briefly browsed the fogdog.com site. (Network logs omitted for brevity.) In HTTP Transaction 2, Zango (installed on my PC) asked 180solutions' web servers for an ad to be shown -- sending the fogdog.com trigger (as shown in yellow highlighting), and receiving a URL to dealsavings.com in response (purple highlighting).
  4. In HTTP Transaction 3, Zango loaded the specified dealsavings.com page in a new window. Via a META REFRESH tag (orange highlighting), the page redirected the new window to a CJ affiliate link which in turn sets a CJ tracking cookie (HTTP Transaction 4) (cookie in blue highlighting).
  5. Observing my cookies (cookie listing), I see that at the end of the events described above, my CJ cookie for FogDog (merchant number 223938; cookie section UCT_223938) includes only the affiliate cookie set by the redirect link from the dealsavings page (blue highlighting). In FogDog's 223938 section of my CJ cookies, I see no surviving reference to the merchant 223938 affiliate cookie section set by the original cash-us.com affiliate link.

Consistent with the rest of my site, the network logs below omit my DUID (my unique 180solutions user ID number) and omit the merchant IDs used by 180 and its advertisers.

In my testing of July 23, 2004, valuemags.com is but one of many merchants that remain targeted by 180solutions double popups. Some targeted merchants use Commission Junction (including this one); others use LinkShare or in-house affiliate programs. Some double popups (including this one) reach affiliate links through redirect servers, while others entail 180solutions sending users directly to an affiliate link via no other intermediaries.

 

Return to top
HTTP Transaction 1: Clicking Through Cash-US CJ/BeFree Link to FogDog
initial affiliate link
GET /bfast/click?bfmid=223938&siteid=30353237&bfpage=bf_advanced
&bfurl=http%3A%2F%2Fwww.fogdog.com%2Fproduct%2Findex.jsp%3FproductId%3D945373
HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://www.cash-us.com/getcode.php3?cid=875
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: service.bfast.com
Connection: Keep-Alive

HTTP/1.1 302 Found
Date: Sat, 24 Jul 2004 02:14:17 GMT
Server: Apache/1.3.27 (Unix)
P3P: PolicyRef="http://service.bfast.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV
Set-Cookie: UID=2|0|20240724; expires=Saturday, 24-Jul-2024 02:14:17 GMT; domain=.bfast.com; path=/
Referer: http://www.cash-us.com/getcode.php3?cid=875
Cache-Control: no-cache
Location: http://service.bfast.com/bfast/click?bfmid=223938&siteid=30353237&bfpage=bf_advanced &bfurl=http%3A%2F%2Fwww.fogdog.com%2Fproduct%2Findex.jsp%3FproductId%3D945373&bfcookietest=Y
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=iso-8859-1

1be
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>Found</H1>
The document has moved <A HREF="http://service.bfast.com/bfast/click?bfmid=223938&amp;siteid=30353237 &amp;bfpage=bf_advanced&amp;bfurl=http%3A%2F%2Fwww.fogdog.com%2Fproduct%2Findex.jsp%3FproductId%3D945373 &amp;bfcookietest=Y">here</A>.<P> <HR>
<ADDRESS>Apache/1.3.27 Server at service.bfast.com Port 80</ADDRESS>
</BODY></HTML>

0

following BFAST redirect
GET /bfast/click?bfmid=223938&siteid=30353237&bfpage=bf_advanced
&bfurl=http%3A%2F%2Fwww.fogdog.com%2Fproduct%2Findex.jsp%3FproductId%3D945373&bfcookietest=Y
HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Referer: http://www.cash-us.com/getcode.php3?cid=875
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: service.bfast.com
Connection: Keep-Alive
Cookie: UID=2|0|20240724

HTTP/1.1 302 Found
Date: Sat, 24 Jul 2004 02:13:56 GMT
Server: Apache/1.3.27 (Unix)
P3P: PolicyRef="http://service.bfast.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV
setting initial affiliate cookies
Set-Cookie: UCT_223938=qIq2QQHF5DgtAc8nVSHx20042060213; expires=Friday, 24-Jul-2009 07:13:56 GMT; domain=.bfast.com; path=/
Set-Cookie: UID=2|AQQHF5MCoiisAABJxIfA|20240724; expires=Saturday, 24-Jul-2024 02:13:56 GMT; domain=.bfast.com; path=/
Referer: http://www.cash-us.com/getcode.php3?cid=875
Cache-Control: no-cache
Location: http://service.bfast.com/redirect?source=BF_10:qIq2QQHF5DgtAc8nVSHx &bfurl=http://www.fogdog.com/product/index.jsp%3fproductId=945373
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=iso-8859-1

186
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>Found</H1>
The document has moved <A HREF="http://service.bfast.com/redirect?source=BF_10:qIq2QQHF5DgtAc8nVSHx &amp;bfurl=http://www.fogdog.com/product/index.jsp%3fproductId=945373">here</A>.<P> <HR>
<ADDRESS>Apache/1.3.27 Server at service.bfast.com Port 80</ADDRESS>
</BODY></HTML>

0



Return to top
HTTP Transaction 2: Zango Request to 180solutions
keyword trigger
GET /showme.aspx?keyword=fogdog.com+fogdog&did=762&ver=5.11&duid=531byhiprtvdgvadrfmfcgtxxyrjmg &partner_id=195252523&product_id=762&browser_ok=y&rnd=22&basename=zango
user id
&tzbias=5&MT=8C5F0B5F1538C31DC2F456CC736BC33B268398A0
&DMT=8C5F0B5F1538C31DC2F456CC736BC33B268398A0&GMA=1&GVI=1&GPI=1
&HMP=709213BFEF2F893692742C6E758547E7BF14D399&ACC=1&bid=0
&SID=KBKBAHUH&OS=5.1.2600.2&SLID=1033&ULID=1033&TLOC=1033
&ACP=1252&OCP=437&DB=iexplore.exe&IEV=6.0.2800.1&TPM=200785920
&APM=45350912&TVM=2147352576&AVM=1985929216&FDS=1768914944
&LAD=1601:1:1:0:0:0&WE=5 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: tv.180solutions.com
Connection: Keep-Alive
Cookie: register=lrd=7/23/2004 6:54:14 PM; partner=lcd=7/23/2004 6:56:21 PM&pi=195252523&pt=315hybrpitvdavgtdrfmoxtgyrxmjg&ci=762&cn=4&cy=us&rg=2505&ct=38972&dma=506&pc=02239&ac=617&bd=12:00:00 AM&sx=&cd=6/26/2004 3:44:10 PM&md=7/13/2004 9:31:38 PM&dlu=12:00:00 AM&glu=7/23/2004 6:54:14 PM&csi=0&li=0&ei=0&chi=0&hii=0&ck=e8952755-1979-45bc-9eae-e54dba9375d1&upbl=False&cv=5.11; guid=e8952755-1979-45bc-9eae-e54dba9375d1; caps=as=0&lad=6/26/2004 1:46:09 PM&askw=0&ladkw=7/23/2004 6:56:20 PM; speedcheck=ls=7/23/2004 6:56:20 PM

HTTP/1.1 200 OK
Date: Sat, 24 Jul 2004 02:13:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: caps=as=0&lad=6/26/2004 1:46:09 PM&askw=1&ladkw=7/23/2004 6:56:20 PM; domain=.180solutions.com; expires=Sun, 24-Jul-2005 02:13:08 GMT; path=/
Set-Cookie: speedcheck=ls=7/23/2004 6:56:20 PM; domain=.180solutions.com; expires=Sun, 24-Jul-2005 02:13:08 GMT; path=/
Cache-Control: private, no-store
Content-Type: text/html; charset=utf-8
Content-Length: 1723

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<meta name="vs_targetSchema" content="http://schemas.microsoft.com/intellisense/ie5">
</HEAD>
<body>
ad to be shown
ad_url: <input id=ad_url name=ad_url value=http://dealsavings.com/dog.htm><br>
ad_takefocus: <input id=ad_takefocus name=ad_takefocus value=n><br>
ad_activationdelay: <input id=ad_activationdelay name=ad_activationdelay value=0><br>
ad_resizable: <input id=ad_resizable name=ad_resizable value=y><br>
ad_scrollbars: <input id=ad_scrollbars name=ad_scrollbars value=y><br>
ad_menubar: <input id=ad_menubar name=ad_menubar value=y><br>
ad_statusbar: <input id=ad_statusbar name=ad_statusbar value=y><br>
ad_toolbar: <input id=ad_toolbar name=ad_toolbar value=y><br>
ad_addressbar: <input id=ad_addressbar name=ad_addressbar value=y><br>
ad_fullscreen: <input id=ad_fullscreen name=ad_fullscreen value=n><br>
ad_statustext: <input id=ad_statustext name=ad_statustext value=><br>
ad_theatermode: <input id=ad_theatermode name=ad_theatermode value=n><br>
ad_id: <input id=ad_id name=ad_id value=66202><BR>
keyword_id: <input id=keyword_id name=keyword_id value=59354><BR>
ad_windowtitle: <input id=ad_windowtitle name=ad_windowtitle value="Brought to you by the Zango Search Assistant"><br>
<INPUT ID=kw_exclude TYPE=text style="VISIBILITY: hidden;" VALUE=".ancestry.com+security+weightwatchers.com+check+filter"><br>
<INPUT ID=ad_shown TYPE=text VALUE="y" style="VISIBILITY: hidden;"><br>

<SPAN class="957085619-06032003"><FONT face="Arial" color="#ff0000" size="5">Thank you
for your patience.&nbsp; You will be redirected to your destination site in a
few seconds.</FONT></SPAN>
</body>
</HTML>



Return to top
HTTP Transaction 3: Zango Loads Advertiser's Site
GET /dog.htm HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: dealsavings.com
Connection: Keep-Alive

HTTP/1.1 200 OK
Content-Length: 1426
Content-Type: text/html
Last-Modified: Wed, 14 Apr 2004 17:15:39 GMT
Accept-Ranges: bytes
ETag: "e878ac1b4422c41:570ee"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Date: Sat, 24 Jul 2004 02:09:00 GMT

<html>

<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
redirect to affiliate link
<meta http-equiv="refresh" content= "0;url=http://service.bfast.com/bfast/click?bfmid=223938&amp;siteid=[deal-svings affiliate ID]&amp;bfpage=homepage">
<meta name="GENERATOR" content="Microsoft FrontPage 4.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<title>mags</title>
<meta name="Microsoft Border" content="none, default">
</head>

<body>

<p>
</p>
<p>&nbsp;</p>

[page continues at length, with many blank lines, <p> and </p> tags, and &nbsp; tags, creating many blank lines]

<!--webbot bot="HTMLMarkup" startspan --><IMG SRC="http://service.bfast.com/bfast/serve?bfmid=223938&siteid=...&bfpage=homepage" BORDER="0" WIDTH="1" HEIGHT="1" NOSAVE >
<A HREF="http://service.bfast.com/bfast/click?bfmid=223938&siteid=...&bfpage=homepage" TARGET="_top"><IMG SRC="http://images.fogdog.com/toolkit/images/homepage_120x60.gif" BORDER="0" WIDTH="120" HEIGHT="60" ALT=""></A>
<!--webbot bot="HTMLMarkup" endspan -->
</body>

</html>

Return to top
HTTP Transaction 4: Advertiser's Site Redirects to CJ Affiliate Link
opening affiliate window
GET /bfast/click?bfmid=223938&siteid=[deal-svings affiliate ID]&bfpage=homepage HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: service.bfast.com
Connection: Keep-Alive
Cookie: UID=2|AQQHF5MCoiisAABJxIfA|20240724; UCT_223938=qIq2QQHF5DgtAc8nVSHx20042060213

HTTP/1.1 302 Found
Date: Sat, 24 Jul 2004 02:13:32 GMT
Server: Apache/1.3.27 (Unix)
P3P: PolicyRef="http://service.bfast.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV
setting new affiliate cookie
Set-Cookie: UCT_223938=qIpmQQHFzEW-AmT8oZyU20042060213; expires=Friday, 24-Jul-2009 07:13:32 GMT; domain=.bfast.com; path=/
Set-Cookie: UID=2|AQQHF5MCoiisAABJxIfA|20240724; expires=Saturday, 24-Jul-2024 02:13:32 GMT; domain=.bfast.com; path=/
Cache-Control: no-cache
Location: http://www.fogdog.com/entry.point?target=z&source=BF_10:qIpmQQHFzEW-AmT8oZyU
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=iso-8859-1

14e
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>Found</H1>
The document has moved <A HREF="http://www.fogdog.com/entry.point?target=z&amp;source=BF_10:qIpmQQHFzEW-AmT8oZyU">here</A>.<P>
<HR>
<ADDRESS>Apache/1.3.27 Server at service.bfast.com Port 80</ADDRESS>
</BODY></HTML>

0



Return to top
Resulting CJ/BeFree Cookies
UID
2|AQQHF5MCoiisAABJxIfA|20240724
bfast.com/
1024
348040704
31120751
2974459440
29651235
*
reference to cookie set by the advertiser that used
180solutions to open a link to the fogdog affiliate window
UCT_223938
qIpmQQHFzEW-AmT8oZyU20042060213

bfast.com/
1024
1078490624
30018606
2973679440
29651235
*