Bodybuilding.com security/cookies compromised

Discussion in 'Commission Junction' started by jimstratton, Apr 3, 2008.

  1. #1
    Bodybuilding.com has quietly acknowledged that a massive cross site scripting security hole has been open for the past year. Due to the nature of the security problem it allowed attackers to gain access to the users cookies and their accounts. They have no way of knowing how many users were affected.

    Has there been any word from commission junction if there will be any adjustments to payments up or down?
     
    jimstratton, Apr 3, 2008 IP
  2. pipes

    pipes Prominent Member

    Messages:
    12,766
    Likes Received:
    958
    Best Answers:
    0
    Trophy Points:
    360
    #2
    For a whole year, thats quite a concern.
     
    pipes, Apr 4, 2008 IP
  3. tvmatt

    tvmatt Peon

    Messages:
    1,076
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #3
    CJ's tracking pixels are hosted by CJ (unless the advertiser does batch transactions), so that should not have an impact on commissions.
     
    tvmatt, Apr 4, 2008 IP
  4. jimstratton

    jimstratton Peon

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    tvmatt you are right. Thanks for the clarification.
     
    jimstratton, Apr 4, 2008 IP
  5. ninjashoes

    ninjashoes Well-Known Member

    Messages:
    1,401
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    138
    #5
    whao thats pretty scary, I hope this doesent effect everyone in some way
     
    ninjashoes, Apr 4, 2008 IP
  6. jimstratton

    jimstratton Peon

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    It looks like they are just ignoring the problem.
    (sorry can't link) http://forum.bodybuilding.com/showthread.php?t=106793071
    There are forum posts with links to exploits on the site and they are ignoring it. WOW!

    Shouldn't they be contacting all their account holders?
     
    jimstratton, Apr 5, 2008 IP
  7. WebDiggin

    WebDiggin Peon

    Messages:
    17
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Wow. This is going to sound like a silly question, but those tracking pixels in the affiliate link. I don't know if I've always kept them in all of my posts. (I'll insert the code as HTML, and then the pixel will mess up the formating, so I'll delete it)

    Have I just made a big no-no? I thought the SID code and the affiliate link itself was what was important. What does the tracking pixel actually do?
     
    WebDiggin, Apr 5, 2008 IP
  8. tvmatt

    tvmatt Peon

    Messages:
    1,076
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #8
    The "tracking pixel" that I'm referring to is separate from the impression tracking pixel (the 1x1 image on most CJ links). The impressions tracking pixel is not required, and most top affiliates (coupon sites, search marketers, etc...) do not use the impressions pixel.

    The tracking pixel that records when a sale is made is hard coded (or dynamically coded) into the merchant's website. On the order confirmation page, the pixel is loaded (since it is included in the merchant's HTML code) and then CJ records the sale.

    Hope this helps to clarify things!
     
    tvmatt, Apr 5, 2008 IP
  9. HighCorral

    HighCorral Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I tried following that Bodybuilding.com link but there site is down. I keep getting a "Service not Available" error.
     
    HighCorral, Apr 7, 2008 IP
  10. WebDiggin

    WebDiggin Peon

    Messages:
    17
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Brilliant. Thanks for clearing it up. I don't think I've encountered a tracking pixel. Just the impression tracking pixel.

    I assume that I can rip the link from any of the text links and use it as a 301 redirect and life should be fine?
     
    WebDiggin, Apr 16, 2008 IP
  11. tvmatt

    tvmatt Peon

    Messages:
    1,076
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Yep, grabbing the link from any text/banner/keyword link & using a 301 redirect will work just fine.
     
    tvmatt, Apr 16, 2008 IP