Page 1 of 1

3rd party AD-Ware : Who's to blame ?

Posted: Sun Aug 05, 2007 1:02 pm
by joomborg
AD-Ware components/modules/mambots i found so far and
was forced to patch :




1) IRCMaxell Cache :
--> it prints a string with "Powered by xxx" and "Generated in xxx seconds" at
the bottom of your html.

Despite the addons is open source and yadda yadda he asks for a 10$
donation to remove his copyright.



2) JamBook : hidden link  "Jambook by xxx yy zz " at the bottom HTML,
he hide it using CSS and the link is tagged "H1".



3) AdSense Module : it randomly displays his own ads using YOUR site.



4) Joomla TinyFCK (JTF) : there's no way to dowload to the addon
unless you click on one of their masked ads.
the link is obfuscated in the bottom below other adsense ads with
the same layout (against adsense TOS).





.
tomorrow i'll update the list, now time to dinner.
feel free to add yours.

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Sun Aug 05, 2007 4:42 pm
by infograf768
These are not security matters.
Post moved to JED for them to investigate.

Please post in the same forum concerning similar questions.

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Mon Aug 06, 2007 2:26 pm
by LorenzoG
Hi Joomborg,

Thank you for your findings and I actually really mean that, since it's very important for us to get to know if any of the extensions listed in JED have any issues.

We regularly get reports from our members and we are dealing them case by case. Sometimes we feel it isn't any serious matter and doesn't really harm the users. Others we feel that the developers have to change and if it serious, then we unpublish the extension until it's solved.  In rare cases, we unpublish the extensions permanently.

I want to give you some feedback about how we see it and what we have/intend to do:
1) IRCMaxell Cache :
--> it prints a string with "Powered by xxx" and "Generated in xxx seconds" at
the bottom of your html.

Despite the addons is open source and yadda yadda he asks for a 10$
donation to remove his copyright.

We feel this one isn't any issue. No hidden strings here, everything is visible. The license is GPL, the source is open source without any encryption and everyone can change the code. The developer has invested a lot of time and energy to give a contribution back to the community for free. We don't see any issue if the developer wants a donation for to spend extra time for to remove this string and in this way get back a very modest contribution for his work.

2) JamBook : hidden link  "Jambook by xxx yy zz " at the bottom HTML,
he hide it using CSS and the link is tagged "H1".

This one was new for us and we can confirm that a hidden link exists. This is actually serious and the website owner can be punished from the search engines if he is unlucky. Here for example what Google write about hidden text and links: http://www.google.com/support/webmaster ... swer=66353
We feel that this hasn't been malicius placed there by the developer for to get advertisement or something. I guess it's more an unfortunate desire to see how many how actually use his work. We have contacted the developer and asked him to remove this line or make it visible and update his extension. If nothing happends, we will unpublish it. I'm quite convinced that this issue will be solved very soon.

3) AdSense Module : it randomly displays his own ads using YOUR site.

We have inspected the code and it's not really true. What it does is that if you don't enter your adsense property number, then the module will use the developers property number. But we couldn't find that it radomly should display his own ads when you have entered the adsense property number.
This is actually quite new for us, since the developer updated his modules for 2 days ago. I looked through his old modules and this behaviour wasn't there. Actually this worries me since the developer doesn't inform about this anywhere. I think the key here is to give the users information about this. We are still discussing how to deal with this issue and we are incline to write an Editors note on this particual extension for to inform our members.

4) Joomla TinyFCK (JTF) : there's no way to dowload to the addon
unless you click on one of their masked ads.
the link is obfuscated in the bottom below other adsense ads with
the same layout (against adsense TOS).

Well, the download link is there on the page with description. But personally I don't like how it's designed and our members have indeed to spend time to search for the download. If it's against TOS then I guess that Google will handle this.

Normally we prefer to handle this issues privately since it involves our relations with 3rd party developers. When we find issues that need to be addressed, then we take contact with the developer in peace and quiet and in most cases, we are able to come to an agreement with the developer to change certain things. We have generally very good contact with the 3rd party developers and we have to mutual trust eachother. It's when someone break this trust (for example unethical behaviour) we get problems. We also get a very strange situation if we publically go out and talk before we actually have talked with the affected developer.

If someone finds any issues with an extension like hidden code or any other issue that can harm the users, please report it privately to the JED team or use the report link you can find enclosed to each extension listing.

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Mon Aug 06, 2007 5:27 pm
by LorenzoG
The developer of Jambook has now updated his component.
The link is now visible, he has fixed some bugs and added new languages.

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Tue Aug 07, 2007 5:15 pm
by joomborg
Dear LorenzoG,

I'm deeply impressed by the fast response and the quick action
you took for this case.

The other thread of mine was closed but let me tell you here
and to all the other devs that nowhere else and with no other cms
i ever encountered such professional and problem-solving attitude.

My sincere apologies to all the guys i may have hurt or offended in this
and other controversial discussions.

From now on I'll certainly do my best to support joomla and spread the word
wherever i can !


Joomborg,

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Tue Aug 07, 2007 5:47 pm
by joomborg
back to the topic :

1) IRCmaxell : well it is GPL and open source, no questions, but
asking 10$ to remove links or ads is what i call "ad-ware" as
in "advertised software" but anyway, the offending string can
be removed in 3 seconds, it's not a big deal.


2) Jambook : i'm very happy to hear that he removed the
hidden link !
As i always say, if nobody complains nothing will ever change.
(I've nothing personally against Jambook, i use it in many
sites and it's the most advanced guestbook for Joomla)



3) Adsense module : if i'm not wrong some users already
wrote in the JED's comments about this issue, that's
how i noticed it as well, but can't say more about it
as i use my own custom adsense mambot and module.



4) JTF :
That's where my blood boils : Google's TOS identifies such
layouts are "made for adsense (MFA)" site and clearly states
that it will lead to a permanent ban.
I've nothing against JTF as an addon, i just find their behaviour
and their marketing completely unprofessional, deceptive and untrustable
and it raises serious doubts about what they could have
cooked inside the addon itself, and their site being called
"hack joomla" doesn't promises anything good.
I don't use JTF nor i'll ever will.





Thanks again and keep up the good work !
Joomborg,
ZhongGuo, People's Republic.

Re: 3rd party AD-Ware : Who's to blame ?

Posted: Tue Aug 07, 2007 6:01 pm
by LorenzoG
You're welcome  :)