256 Kilobytes

Spoofing Browser URL Previews

Articles in Unintended Behavior and Exploits | By Hash Brown

Published 4 weeks agoWed, 22 May 2019 12:41:22 -0700

Not illegal, not a single government was even hacked but this is a great little trick for those trying to trick people.

95 views, 2 RAMs, and 3 comments

This is something I came across a while ago, it stuck in my head as something that affiliates could use very easily to help boost click through rates to their offer.

For affiliate marketers getting people to click is important. It's pretty much what everything is about but getting more savvy and technical internet people to fall for the "trick" and click a funky looking URL with "&aff=1282" on the end is hard.

This gets even harder when you're using networks like Share A Sale which put all clicks through their domains which look untrustworthy. 

Right now a lot of affiliate websites use redirects to hide their dodgy looking links, but again to any savvy internet user who is going to check the URL preview before clicking it's going to look just as dodgy.

If you're promoting an affiliate offer from a (made up) company vpnservice.com and your URL preview looks like this, you're probably going to lose some clicks.

But... What if you could change the preview URL in your browser to be something far more friendly looking before a user clicks?

How to spoof URL previews

I don't actually know what the fuck this little preview box is called and apparently other people don't either... but for the sake of this article lets call it "URL preview window".

It's purpose is to show you the URL of a link before you click it and technical people or regular internet users usually check this when viewing a website and potentially landing on a page they don't expect which may contain porn, viruses and all this great stuff.

If you are promoting an affiliate offer to a target audience who do this naturally, you may find that your offer CTR is effected. That sucks.

Or of course you can do this for other things... I will let you get creative here on your own. 

Method

This method is very simple, and you can try it here.

This is our test link. The URL preview should show google.com but when you click you see 256kilobytes.com.

The code for this is here:

<a href="http://www.google.com/" onclick="this.href='https://256kilobytes.com'">Anchor Text</a>

Well that seems really fucking simple? Why did you even write this you dumb fuck?

Thanks for the feedback.

I don't see many/anyone doing this on affiliate sites. It seems extremely simple (it is) and very effective...

But it has limited uses, most CMS's would strip the JavaScript from the link (usually allowing this in post content is a bad idea).

So, we need a WordPress solution.

How to do this in WordPress

You could build a function, but fuck that. Lets just use a plugin like a black man.

We are going to use Code Embed, a very simple and mildly popular plugin that allows us to create short codes. This will embed our javascript into post content without being stripped. Nice.

It's very simple to use, install as normal and head to the custom field section of a post. (If you can't see it then you need to click screen options and select it)

It should look something like this, fill in your code and set a field name and save.

We can then embed the code as per the very simple instructions our plugin gives us.

It is looks like this.

But of course, when you click you go to the affiliate link.

Warnings for WordPress People

If you have certain analytics programs installed that are adding their own onclick events, it will break everything and you will be sending clicks without your affiliate tag.

This is true for Monster Insights, a very popular Google Analytics plugin.

There is an option for disabling this, but I don't want to install a plugin that embeds spyware on my website so work it out yourself (or just put your GA code into a function, properly).

Warning for Affiliates

Some offers make hiding your URL against their terms, meaning if you got caught you could be in trouble and get banned from the offer or network.

Amazon is one example of this.

Read the terms of service and make sure it does not break any rules.

This seems very immoral and you should go to hell

Currently affiliates are left with 2 options:

  • They use redirects like affiliateblog.com/offers/the-offer-url as an attempt to hide affiliate links. You have no idea of knowing where these links take you either.
  • The network/merchant force you to use silly link shortners like share a sale, again... your users have no idea where they will land.

So while this trick could be used for dirty tricks, it doesn't really make sense to say this is the case when the two current options have the exact same problem.

Users Who Have Downloaded More RAM:
Huevos Rancheros (4 weeks ago)
Scuffed Dog (4 weeks ago)
🐏 ⨉ 2
Posted by Hash Brown 4 weeks ago 🕓 Posted at 22 May, 2019 12:41 PM PDT

Profile Photo - Hash Brown Hash Brown Internet Activist &... United State of Euro...
🗎 54 🗨 363 🐏 155
Staff
Profile Photo - Huevos Rancheros Huevos Rancheros
🗎 16 🗨 77 🐏 42
Staff

Very nice dear. I'm literally hacking my local government with this right now

Download more RAM. 🐏 ⨉ 0 Posted by Huevos Rancheros 4 weeks ago 🕓 Posted at 22 May, 2019 13:03 PM PDT
Profile Photo - August R. Garcia August R. Garcia LARPing as a Sysadmi... Portland, OR
🗎 149 🗨 769 🐏 211
Site Owner

muh right click -> open in new tab / mousewheel click. There's plausibly some workaround for that. IDK LOL.

Download more RAM. 🐏 ⨉ 0 Posted by August R. Garcia 4 weeks ago 🕓 Posted at 22 May, 2019 13:12 PM PDT

Sir, I can do you a nice SEO.

Profile Photo - Hash Brown Hash Brown Internet Activist &... United State of Euro...
🗎 54 🗨 363 🐏 155
Staff

> muh right click -> open in new tab / mousewheel click. There's plausibly some workaround for that. IDK LOL

Why would you even do that

Download more RAM. 🐏 ⨉ 0 Posted by Hash Brown 4 weeks ago 🕓 Posted at 22 May, 2019 13:41 PM PDT

"THAT DOG IS GETTING RAPED" - Terry A. Davis

Post a New Comment

To leave a comment, login to your account or create an account.

Do you like having a good time?

Read Quality Articles

Read some quality articles. If you can manage to not get banned for like five minutes, you can even post your own articles.

View Articles →

Argue with People on the Internet

Use your account to explain why people are wrong on the Internet forum.

View Forum →

Vandalize the Wiki

Or don't. I'm not your dad.

View Wiki →

Ask and/or Answer Questions

If someone asks a terrible question, post a LMGTFY link.

View Answers →

Make Some Money

Hire freelancers and/or advertise your goods and/or services. Hire people directly. We're not a middleman or your dad. Manage your own business transactions.

Register an Account
You can also login to an existing account or recover your password. All use of this site is subject to terms outlined in the terms of service and privacy policy.