Tracker Playbook
Tracker Playbook
@TrackerPlaybook

Postback security — the anti-spoof hardening checklist

Postback security — the anti-spoof hardening checklist

An unsecured postback URL is a public endpoint anyone can hit to inject fake conversions. Harden it in this order.

— Add a secret key parameter to the postback URL that only you and the network know. Reject any postback missing or with the wrong key. This alone blocks casual spoofing.
— Allowlist the network's postback IP ranges if your tracker supports it. A conversion from outside the network's IP space is a forgery.
— Enforce that the click-id must match a real logged click. Reject any postback whose click-id was never issued by your tracker.
— Enforce a sane time window. Reject postbacks for click-ids older than the offer's realistic conversion window. A conversion on a 6-month-old click is noise or fraud.
— Rate-limit per source. A flood of postbacks in seconds is an injection attempt, not organic conversions.
— Log every rejected postback with reason. A rising reject count is your early warning that someone found and is probing your endpoint.

Validation:
— Fire a postback with the wrong secret key. Confirm it is rejected, not recorded.
— Fire one with a fabricated click-id. Confirm it logs as orphan or reject, never as a sale.

Save this SOP. Harden every postback before it goes live.
Этот пост опубликован в Telegram-канале Tracker Playbook. Подписаться можно по ссылке: @TrackerPlaybook.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.