This is my first post on WW - I'm a new memeber. I think I have found a big security hole in Adwords recently, which can (and probably does) lead to click fraud abuse. I discovered it while trying to figure out why Google could not find click fraud in our account, and our logs reported such. I think it's quite serious.
I have spoken to our people (client reps/API guys, etc) at Google, but the flaw is not fixed and no one has gotten back to me. I have tested this flaw by click frauding our Google account and Google does not detect this (although, in reality, they can't).
What's the best way of getting Google to close this hole in their system? Do I publish a report about it? Obviously, I'd rather keep it quiet, but I'm not getting anywhere with them.
Any advice?
I have spoken to our people (client reps/API guys, etc) at Google, but the flaw is not fixed and no one has gotten back to me.
I second Shak in welcoming you to WebmasterWorld, VinnyL
In your post you mention having a rep at Google, and I'm assuming that you mean that you have a rep for your AdWords account.
If that's correct, then my best suggestion would be for you to put your information in an email, contact your rep once again, and ask them to forward the email to AdWordsAdvisor, per my request on WebmasterWorld.
(I notice that you're new to the Forum as of earlier this month - so perhaps I should mention that I am a long-time AdWords employee, and that I've posted here for some time as a Google representative, with the blessings of the Forum owner and moderators.)
In any case, I'd be happy to put your information in front of the right folks.
AWA
David: The last thing I want is anyone finding out how else to click fraud our account! We have enough problems as it is!
Mark: I did not do anything wrong, I can't explain what though on the board. It wasn't even multiple clicks.
Thanks AdwordsAdvisor - I will be sending a mail through explaining everything in detail - maybe I'm wrong?
<snip>
Well, I am going to do NOTHING, except for posting the message here and hoping somebody from google reads the message (I would kindly ask the moderator not to erase the URL).
Meanwhile, I urge you to find a site that violates google's TOS and contact them directly. Let's see who gets google to act first.
[edited by: Brett_Tabke at 8:48 pm (utc) on June 16, 2005]
[edit reason] no specific sites please [/edit]
It appears they put a random image to the left of each AdWords text ad to make it seem like an image ad, in order to increase the CTR.
Well, it worked on me. I clicked an ad just to see if that's where the full-size image was. It wasn't.
[edited by: eWhisper at 9:23 pm (utc) on June 16, 2005]
[edit reason] No Outing Sites [/edit]
It appears they put a random image to the left of each AdWords text ad to make it seem like an image ad, in order to increase the CTR.
"Publishers may not label the ads with text other than "sponsored links" or "advertisements." This includes any text directly above our ads that could be confused with, or attempt to be associated with Google ads."
What you see is an image that reads "Games" right above the block of ads. Obviously, Joel's site got viewed by Google's staff a thousand times because of his e-book, and what he does does not really violate Ad Labeling section. So a lot of people started using images creatively to increase their CTR - and it works very well. But his person (discussed in prior post) went too far. I think it violates Google's TOS ("drawing any undue attention to the ads.")
I don't really care and won't report the site to Google directly, my only intention is to find out if and how fast you can get reaction from Google by simply posting detailed information about a perceived problem in a professional forum, like this one.
[edited by: eWhisper at 9:24 pm (utc) on June 16, 2005]
[edit reason] Don't drop URLs. [/edit]
[edited by: engine at 9:39 pm (utc) on June 16, 2005]
[edit reason] TOS [/edit]
David - I know what you are saying, however cynical, but somehow, I'd rather exhaust all other options before publishing my findings for public review. Pointing out flaws on public forums normally causes more harm than good - in the case of Microsoft, it results in innocent people getting viruses, etc.
I'm pretty sure that AWA will come back to us with something soon. Who knows - maybe I'll get a reward for keeping it quiet ;-)
Failing any response from Google or if they don't think it's serious, I'll post the email I sent to AWA and you guys can check it out. I could be wrong, but I tested everything before I sent it off and it definitely looked flawed.
MOD Note - Please Read the WebmasterWorld TOS and do not post e-mails. Thanks
[edited by: engine at 10:35 pm (utc) on June 16, 2005]
[edit reason] Terms Of Service [webmasterworld.com] [/edit]
I see that this thread has been pretty active today - and just wanted you know that your information was received and was passed on, as I mentioned earlier.
Because I'm not a part of the team looking into this, I'm not certain when you'll hear back, although I suspect it will be soon. Once I saw this thread, though, I briefly chatted with a couple of the folks who are looking into your email, and I am certain that it's being investigated thoroughly.
AWA
Any update yet, AWA?
eyeinthesky, I actually don't anticipate having an update on this myself. I've passed on VinnyL's info, but beyond that I am not a part of the research happening at this end. Any further communication would come from the team doing the research, and would go directly to VinnyL.
AWA
I haven't heard anything yet. If I don't hear from them soon, I'll just assume it wasn't serious and I'll post the email to you guys. I'm busy making a screen recording of the "flaw", just in case it gets fixed and we get a "it was never broken" reply :-).
I think we're all experiencing enough uncredited click fraud to worry about this issue, and as good as Google's systems are and as honorable as their intentions, if there's a flaw, they're not going to be able to detect the fraud, hence my concerns.
AWA - can we say that if I don't hear a response back from them that I post the email to the forum on Friday?
V
AWA - can we say that if I don't hear a response back from them that I post the email to the forum on Friday?
VinnyL, I probably should not be a part of your decision making loop on this. Were it my decision, however, I guess I'd ask myself what is to be gained by posting, and go from there.
As an update, I've pinged the team to whom I forwarded your info - and am told that they'll contact your rep shortly.
AWA
Thanks. I look forward to hearing from them. As long as I'm comfortable that it's being taken seriously by them (or I'm just talking crap), then I'm happy to keep it quiet. As previously metioned, my aim is NOT to divulge it - and I will definitely keep it under wraps!
Thanks for following up.