I don't have any plugins other than Adblock.
I'm about to convert my laptop to an Ubuntu machine, so since everything will be formatted and fresh, I'll see if I get that popup.
I don't have any plugins other than Adblock.
I'm about to convert my laptop to an Ubuntu machine, so since everything will be formatted and fresh, I'll see if I get that popup.
Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.
Interesting ... I've certainly never seen it myself ... (I use four different browsers) nor have any of my writers. We also never promoted Betway to UK users so I don't expect to be displaying BetWay ads (let alone pop-ups) to a UK IP address.
Additionally, we have no "plug-ins" - it's a WordPress free site - and I've checked the index page (and reloaded it) and .htaccess files and can see no sign of unsolicited calls that would result in a pop-up.
That leads me to believe it IS something to do with the way you are getting to the site WATP.
- It might be a toolbar spy-ware thing.
- It might be something hooking into the GPWA jumps?
Very strange ...
An easy way to test MIGHT be to download a browser you have never used and so is toolbar free - perhaps Safari? - do your IP clearance thing - and type in the address? Still there at BetDistrict and/or GoonersGuide et al?
@WATP well, thank you for helping me out anyway and verifying the page after the removal of the file. I have nothing left to do apparently.
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
@TheGooner - sent the message, thank you in advance.
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
Cheers for the update Gooner, as I was starting to think, it must be something on my end, but as I mentioned, I'm so overly cautious and check with scanners daily. There's also nothing obvious like a toolbar etc. I disable everything, not a single toolbar or any rubbish installed and I have firewall/antivirus permanently running. My feeling is here, it's something that an antivirus wouldn't bother to detect that has bundled with something or.. somehow it's triggered by clicking through from GPWA.
I downloaded Safari, rebooted and loaded GoonersGuide - nothing happened. Rebooted IP, went to GPWA with Safari then loaded your site from your sig, and there was the message again (image attached). So it's surely not a firefox-based thing, i've already tested with all Firefox plugins disabled and the message still appears anyway.
Absolutely confused to where it's coming fromYou can't right click or do anything with the box as well to view a source code or get any info, maybe there's a browser or plugin or something to do this or de-obfuscate it somehow! Or if there's any specific registry entry that Dan and I could check and I'll get the raw aff link for whatever idiot created this. I got a quickglance of it pre loading Betway and it was "doubleclick" but mispelled -> "doubilclick" or something.
On an unrelated note to this (but the purpose of the thread, apologies for that!), that AffiliateBible post was a great read
Small update:
I used a screen recorder to video the loading of the site and got the urll, was way too quick to copy & paste. The misspelling in the domain is the actual url that appears quickly before betway loads and I think i've typed out the rest correctly.
ad.doublcilck.net/clickbw;r|h=v4|5193|0|0|*|b;468|60;8558006|855902| 1;;~sscs=
Googling that URL, I stumbled upon:
reddit.com/r/techsupport/comments/1khe2t/addoublcilcknet/
Last edited by WATP; 9 June 2014 at 10:29 pm.
From my laptop with a formatted disk and a fresh Lubuntu install I didn't see the popup on either site (direct URL typing). But it's still the same IP as the day before when I posted the screenshot. But since you, WATP, managed to replicate the issue on a clean machine is must be site-related.
I repeat, I never saw that popup on any machine or any site before visiting Betdistrict (I'm almost certain I used Rostick's sig link). It sounds much more like a site hack than a PC hack.
WATP, can you make further checks to see does the popup appear exclusively when you click the GPWA link to the site?
Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.
Hi Dan,
Cheers for the info. Yeah I think the IP thing is one thing we can be sure off, it will only display once, at least "per 24 hours" or something must be the way it's coded. I can never replicate the popup, even going from betdistrict to gooners etc, an IP reboot must be done.
Right, I did a little test based on what you asked.
1) Rebooted, loaded gooners by typing the url: No Popup
2) Rebooted, loaded betdistrict by typing the url: No Popup
3) Rebooted, loaded gooners again by typing the url: No Popup
4) Rebooted, loaded the GPWA thread directly by typing the url. then visiting betdistrict: No Popup
5) Rebooted, loaded GPWA, went from "latest posts" to the main page, to forum, and back to the thread.. Clicked on Gooners Sig, and the popup occured again, same one for betway.
Since I've kinda eliminated Firefox as an issue and it seems to be triggered by or from GPWA. Heres some other third party things I have installed at some point from the 'uninstall a program' list in Windows 7, that might have some rubbish bundled, see if we can match them up and I'll search the code of the programs to the best I can! Didn't bother listing stuff like Skype or 'official' stuff.
Do you have any of these:
- Bandicam, NaturalReader, mkv2vob, WinXDVD, CopyTrans Control, Dreamweaver/Photoshop (probably not official, a friend gave me them years ago), 3gp player, AutoHotKey, SMPlayer, some thing called GSA I've never used (an seo thing), imagecompressor, RollerCoaster Tycoon (downloaded), Farming Simulator (laughing
downloaded copy), Bandisoft MPEG decoder, Ashampoo burning studio, Trillian.
No obvious stuff bundled, or any "do you want to install this toolbar" type rubbish that comes with alot of freeware. I just find it hard to believe that Gooner etc wouldn't have noticed some rogue code in their index.php files or whatever, especially since he mentioned it's not Wordpress he's using, I'm sure we've both got something installed. You mentioned you've never seen it before since visiting BD. I have a feeling I've seen it before when visiting bookiesoffers site, and that would then be the 3rd member to have been hacked which seems unlikely, but who knows! : )
Just found this also regarding the pop up from the good man himself in August 2013:
https://www.gpwa.org/forum/strange-p...te-212883.html
Cheers Dan.
Last edited by WATP; 10 June 2014 at 8:49 am.
Nope, basically the only things I have installed on my PC are GIMP, FileZilla and coding tools such as Notepad+, PyLab, Embarcadero, Grep, Xenu link sleuth and Entnought Canopy. No toolbars.
As far as I can tell, no one managed to replicate the issue without clicking the link on GPWA.
Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.
I ran about 3 scans on betdistrict. Everything seems clean. betway said it`s hard for them to do something about this issue (I gave them the URL WATP provided the first time).
Also read the threads WATP linked to, seems there`s no answer on this issue. As I previously said I questioned about 30 writers of mine on this issue and not a single one of them encountered the popup. I doubt there`s anything wrong with Dan`s or WATP`s software - I`m not sure it`s GPWA either considering WATP linked to another post of a webmaster that was getting the popup independent of GPWA. If it`s me however, I am out of solutions.
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
Rostick: Thanks for all your help here and I'm confident you have no need to worry, everything seems to point to it not being on your end. Sorry you're thread has kinda gone wayward.
Dan: Out of your list, the only thing we both have is Filezilla which I use regularly. Unless it is that (the guy that made the software is notorious for being an a**, although that's just a side matter), things are starting to point weirdly to GPWA, possibly some sort of hack on the forum, but no idea if that would be even possible to bring up a popup on sites after it's been loaded from an outbound link.
one of my writers got back to me and said that he encountered the popup a couple of days ago .... he does not visit gpwa. he`s from Romania
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
[QUOTE=WATP;758719]Rostick: Thanks for all your help here and I'm confident you have no need to worry, everything seems to point to it not being on your end. Sorry you're thread has kinda gone wayward.
[/QUOTE]
I`m the one who should be thanking. yes, the thread has gone wayward, but this is an important issue as well.Of course i don`t have conversions if let`s say 50% of that traffic would get that popup.
Betdistrict.com - free betting tips & previews
Happybags.ro - romanian e-commerce website
WW2HistoryBook - World War Two Library
Cheers for the kind words Rostick!
Ok, I have searched to the ends of my pc and I can't find anything. I spoke to someone who is pretty smart when it comes to these things and his idea was to check for any javascript... so...
I went back to the 3 websites in question here where the pop up is present (and I also got the pop up to appear earlier without visiting GPWA signatures on a side note, so it's not just the signatures).
TheBookiesOffers, GoonersGuide and BetDistrict all have only 1 thing unque in their html code that they share. The GPWA Certification Javascript. I've tested a few other sites with the reboot etc, and It seems to be specific to sites with the seal code in play. Sounds crazy, but makes sense in that I cannot replicate it on my own sites or other "non-gpwa certified" bookie websites via the reboot thing and we all share similar betting keywords.
DanHorvat (11 June 2014)
Is there a bug in the gpwa code?
Sent from my iPad using Tapatalk
Visit Play Slots 4 Real Money and Casino Slots Money for trusted recommendations and tips on the best casinos.
No idea. I've reset my IP a million times tonight trying everyone's sigs across the forum and the only site's displaying the message are the ones carrying the GPWA javascript thing. Although, some sites carrying the logo itself don't display the popup, but i've realised that's because they have not used whatever javascript code the others are using for the certification thing.
Your site, "every1bets" is fine, but I see in the source code that it doesn't have the full javascript code that Gooner etc do. Who knows, but this seems to be the likely culprit to me![]()
edgarf76 (10 June 2014)
Quick update. I've nothing better to do tonight, so I went through a massive list of the GPWA Certified programs from their page. Most aren't carrying the GPWA logo and the ones that are it's usually a self hosted image, just a standard <img src> thing. Regardless, I went through them all viewing the source code after each load (a bit sad if I'm honest, but if it can help others then what the heck).
- All sites that are listed but carried no logo at all or any reference to a GPWA seal were fine.
- All sites carrying just a standard GPWA image and no JS were fine.
- All 4 sites (new ones not mentioned so far) that I found carrying the javascript version of the code brought up the pop up
I also noticed the message and final url varied slightly depending on the site but it was the same "doubleclick" thing, variations of the spelling as well. One went to "spinpalace" instead of Betway after clicking ok. I'll leave it to others to throw up some ideas on what this is and why it's there, not going to jump to any conclusions of the 'why', but it's something to do with the GPWA certification javascript for sure.
If you want to test, gooner or betdistrict could take out the code and I'll try again. It's a 100% popup "success" rate for me at the moment with you guys websites after rebooting.
Doesn't sound impossible - that GPWA script is probably doing more than just displaying a badge and some hacker could have injected some code into it - and I do like a good theory.
I'll remove the GPWA script overnight and we will see what happens with a retest.
UPDATE :
Easy to remove - already done!![]()
Last edited by TheGooner; 10 June 2014 at 11:42 pm. Reason: UPDATE :
WATP, this is brilliant! Kudos!
I'm using a custom version of the GPWA seal. This is how it looks like:
<a onclick="window.open(this.href,'','scrollbars=no, resizable=no,location=no,menubar=no,status=no, toolbar=no,left='+(screen.availWidth/2-305)+',top='+(screen.availHeight/2-330)+',width=610,height=660');return false;" href="http://certify.gpwa.org/verify/xxx/"><img style="margin-left: 3px;" src="https://www.gpwa.org/forum/images/xxx.jpg" alt="xxx" width="73" height="32" /></a>
So I'm not loading any script, the entire code is here to create a popup which displays the page related to me and the site.
Professional bizdev can help you, the affiliate, to negotiate better terms with casinos. PM for details and a free evaluation of what I can do for you. All geos.