- France
- http://geoffrey.frogeye.fr
- Joined on
2016-02-08
I'm not currently focusing on ads, unless they do some tracking too (most of them are). However I can easily create another list with ads included since they also use this technique. There will be not a lot of material, but it's definitely possible.
While I set that up, do you mind answering a few question for "research"?
- The link for the Javascript is giving me a 403, it's only on my side? I guess it's because I'm in Europe?
- Usually first-party trackers/ads use the same domain (e.g. ads.jiji.com) as some trackers blocks anything not *.jiji.com. Here, it's using sony.net. Do you know if both sites are related somehow? Same question for ozmall.co.jp and enhance.co.jp (from geoffrey/eulaurarien#18).
Hi! Sorry for taking long to answer, I missed the notification.
Thanks for the info! Like A8 and Ebis, I can't seem to attest the real world usage from here (I tested a lot of websites from your list, but I couldn't see one trying to access the subdomains. Maybe it doesn't trigger from Europe and/or you need to browse a bit), but this does look like CNAME spoofing indeed, so I trust you on this one :)
This should go live partly tonight, and the rest will follow during the week.