Select Page
Are Affiliate Cookie Hijackers Stealing Your Commissions?

Are Affiliate Cookie Hijackers Stealing Your Commissions?

If you earn a living – or even just spending money – selling stuff online as an affiliate, you should be concerned about cookies.

Digital cookies are the behind-the-scenes gizmo that credits you with a sale generated by a web page visitor. What you may not realize is that it is entirely possible for a clever hacker to hijack those cookies and end up with a sale that should have been credited to your account.

We’re talking big money. Shawn Hogan drew the attention of the FBI when he redirected around $28 million from rightful affiliates to his own account over the course of a few years.

The process in question is known as cookie hijacking or session hijacking.

To protect your cookies, it’s time to get serious about cybersecurity. It’s time to learn what cookies are, how they get hijacked, and what you can do minimize the risk.

Understanding Cookies

A cookie is a small packet of data that a web server transfers to a browser when someone visits a web page. Think of it as a message that originates with the server and is received by the visitor. Unless the visitor has blocked cookies, that data downloads onto the system and makes it easier for the page to load the next time the visitor returns.

That’s the main purpose of cookies: to make visiting a page simpler by ensuring it loads a little faster. It also helps the owner of the page have a better idea of how many visitors the page generates, if there are return visitors, and in general keep up with traffic patterns.

As it relates to affiliates, those cookies also make it easier for you to get credit when a consumer purchases something via your page.

How Can They Be Hijacked?

Cookies are dead simple, which may be why they are often overlooked as a means of committing a crime. All it really takes is for a hacker to seize the cookie and make a minor alteration.

http cookie hijacking flow diagram between hacker and computer

The next time a visitor lands on your page the cookie ensures that the hacker’s content loads. In most cases, it will be an almost perfect mirror of the original page. What’s different is the packet of information downloaded for the session is not original. It’s been altered. That sets the stage for the hacker to control what happens next.

What Does this Mean For Affiliates?

Why would cookie hijacking matter to an affiliate? After all, doesn’t the visitor use the URL to get to the right place and make a sale? What does the cookie have to do with it anyway?

The thing to remember is that the cookies make loading the order page easier. If you alter the data in the cookie so that the affiliate ID is no longer the same, the credit for that order is redirected to another source. That’s because the cookie is often stored in the raw URL for the session. Alter the cookie by changing the affiliate ID and the end user doesn’t really notice anything.

In other words, it appears that the consumer is placing the order with you, but it’s actually being placed with someone different. You never get credit for the sale and certainly don’t receive a commission. That makes this little malfeasance a form of affiliate fraud.

How Do You Know If Your Affiliate Cookies are Hijacked?

Cookie hijacking is difficult to spot. In fact, it would be almost impossible to detect when it happens during a live session. Whether the session hijacking is active or passive, you only have a chance of identifying the damage once it’s done.

One sign that something is not right has to do with the performance of the web page. If it begins to function erratically for no apparent reason, that could mean something has been altered. Alternatively, the page shutting down can be an indication something has been changed. At this juncture, you may want to check the cookies related to the page closely and see if the affiliate ID or even some other aspect of the cookie code is not as it should be.

If your affiliate partner emails or texts you when individual sales occur, compare that information to the commission report. If they don’t match, and there’s no evidence of returns or canceled orders, someone else is ending up with your commissions.

Are There Ways to Prevent Hijacks?

Preventing a hijack is actually simpler on the visitor side. If the page visitor has up to date malware and antivirus software, the protections in those programs will likely spot that something was changed during a session. This gives the individual the opportunity to end the session before completing a transaction. The problem is the high rate of old malware and antivirus software in use.

Your affiliate can provide some support in terms of preventing cookie-jacking. Depending on how the servers download cookies and what sort of security is used for your customized affiliate page, it may be possible to prevent hacking software from modifying the cookies and the session ID that’s generated.

Create Your Own Encrypted Internet Connection

It’s not as complicated as it sounds. The concept of a virtual private network or VPN is coming into its own and likely will become an indispensable component of internet connections before too much more time has passed.

A VPN works in conjunction with your ISP. It is a separate service that encrypts the data that flows between your device and the internet. You don’t have to be a cryptographer to realize that encryption makes it harder for a hacker to complete his task. The extra ten or so bucks a month is money well-spent.

how does https work and differ from http - simple diagram

Make sure your affiliate pages use HyperText Transfer Protocol Secure (HTTPS) rather than HyperText Transfer Protocol (HTTP). Doing so adds another layer of protection by scrambling the code that’s shared between the originating server and the recipient

The Bottom Line

You don’t devote time and energy to building a business only to have someone else steal sales as certainly as if they reached over and grabbed twenty bucks from your wallet. Make it a point to educate yourself about online security. Subscribe to a blog or two. You don’t have to be a techie to stay updated on the latest threats and keep solid malware protection in place.

 

Conversion Rate Optimization

Conversion Rate Optimization

Conversion Rate Optimization (CRO) is a fancy term for a dead simple task – getting more of your website visitors to take the appropriate action. Note we said that the visitor’s side of the equation is simple, and it is. All they have to do is sign up for an email list or buy a product or service – whatever it is that is the reason for your site’s existence.

For the rest of us website owners desperately seeking the Holy Grail that will ratchet our conversions up, the task is more complicated, especially if you’re new to the whole art/science/voodoo that is modern CRO.

CRO path

But you can rest easy. Even if you’re the wettest behind the ears newbie imaginable, we’re about to open up a world of possibilities by presenting the first four CRO tools you should consider as you begin (or continue) your battle to make a buck online. Easy to use but powerful, get ready to have your wildest dreams of profit come true. Just having a little fun there, but you never know…

Why You Should Care About CRO

In case you feeling compelled to dismiss the importance of a better conversion rate, consider the following:

  • Higher conversion rate = better ROI
  • You can make more money with the same amount of visitors
  • It’s the best way to circumvent online impatience from visitors

Achieving these three goals is all in the data and how you analyze it. Let’s get started.

Tool #1 – Hotjar

Powerful but with a short learning curve, Hotjar allows you to analyze a website up to 2,000 pageviews a day at no cost. For 10,000 pageviews a day, your price will be $29 a month and it goes up from there. What can you do with Hotjar? Quite a lot, actually.

Features include: polling, surveys, visual heatmaps, conversion funnel tracking, form analytics, visitor recordings, and more.

The cool stuff: If you haven’t heard about visual heatmaps, they’re all the rage in CRO conversations. Put simply, they allow you to identify hot and cold spots on your website – in other words, where visitors click and where they don’t. If your prize BUY NOW button is in the deep freeze, a heatmap lets you know a redesign is in order.

Example of a heatmap

Visitor recordings can also be helpful as you launch a CRO strategy. Did you ever wish you could stand behind a visitor’s shoulder and watch as they navigate your site? Being able to see exactly where they got bored, confused, frustrated, or simply leaped up to answer the call of nature would be immensely valuable. That’s what you can do with visitor recordings. Play back the click journey(s) and you’ll soon be able to tell where the process falls apart.

Tool #2 – Crazy Egg

Crazy Egg is definitely a major player in the CRO field. With a generous 30-day trial period and pricing that starts at $29 month, this service allows you a chance to practice before committing actual money.

The cool stuff: The big three offerings from Crazy Egg are heatmaps, visitor recordings, and A/B testing. We’ve already touched on heatmaps and visitor recordings, so let’s define A/B testing, which is a basic but critical part of CRO.

The overall process of CRO is to figure out what isn’t converting on your website and change it. The simplest way to do that is create nearly identical pages and split your traffic between them. Note we said NEARLY identical. By changing one thing at a time on a page, like say the color of the “buy” button, you can compare which version converts better.

By continuing to make one change at a time, you incrementally improve your conversion rate.

Tool #3 – EyeQuant

While heatmap tools are pretty standard fare with most CRO tools, EyeQuant has taken a different approach. Rather than relying on visitors’ actions to discern hot and cold spots on a web page, this company uses artificial intelligence (AI) to predict the areas that draw visual attention which, obviously, is a precursor (and perhaps more valuable measurement) to action.

The cool stuff: Where heatmaps collect and combine real world site interaction that plays out over time, EyeQuant’s Attention Map lets you upload a snapshot of a web page and delivers the verdict within a few minutes. This almost instant analysis comes to us courtesy of technical AI advances that make an educated guess as to where human eyes will go first.

One thing to keep in mind is that this service seems to work better with e-commerce websites. It tends to automatically decide that text heavy sites are too busy. While EyeQuant’s price might appear to be a state secret, we’ve managed to determine that entry-level packages start at around $100 per month.

As to whether your needs can justify the price – your call – but the case studies are pretty impressive.

Tool #4 – Google Analytics

The old war horse of CRO is something you’d have a hard time avoiding if you spend much time at all online but just because it’s been around a while doesn’t mean it’s past its prime. Not only has Google Analytics (GA) been revamped in recent years to make it even more valuable for CRO practitioners — it’s free. Included in GA are all the usual suspects of CRO like A/B testing, exit page, behavior flow, and more.

Page load speed is important

Final Thoughts

An often overlooked part of tuning your website for maximum conversions is how quickly it loads. Everything else being equal, a faster website means higher conversions. You’re doing yourself a serious disservice if you don’t pay attention to this. While we’re not trying to turn you into a programmer, there is a lot to accomplish through a few relatively simple strategies related to file compression.

Check out this Pingdom page to find out how quickly your website loads. Keep in mind that Google recommends two seconds or less and even uses this metric as part of its vaunted algorithm that determines where you place in search results. Improving site load speed is an ongoing parallel process to focus on at the same time as you learn to use the CRO tools we’ve discussed here. Good luck!

March Update – Ecommerce

March Update – Ecommerce

What is eCommerce?

Given some recent questions we have received, we thought it was time for a review of the fundamentals of eCommerce for aspiring web professionals.

Electronic commerce or eCommerce is a term for any type of business, or commercial transaction. It involves the transfer of information across the Internet. It covers a range of different types of businesses, from consumer based retail sites, through auction or music sites, to business exchanges trading goods and services between corporations. It is currently one of the most important aspects of the Internet to emerge.

This eCommerce article provides information about selling online products and also about how to develop an eCommerce strategy.

eCommerce websites

eCommerce Basics

To review the basics, one should read this article written by Ajeet Khurana an author, educator, mentor, angel investor, and speaker for eCommerce and online business.

(more…)

Interview with David Braun from TemplateMonster

Interview with David Braun from TemplateMonster

We had the opportunity to communicate with David Braun (co-founder and CEO of TemplateMonster.com) recently. TemplateMonster is a marketplace featuring 46,000 templates for many different types of websites.

Why should Web Professionals care about this?

  • TemplateMonster can save you time
  • Templates exist for major platforms (WordPress, Drupal, and much more)
  • This means you can speed your workflow

David Braun is a co-founder and CEO of TemplateMonster.com. This company is the oldest and the most experienced on the market in this area. We invited David to talk and provided some questions for our discussion.

David Braun, co-founder and CEO of TemplateMonster.com

David Braun, co-founder and CEO of TemplateMonster.com

What is TemplateMonster.com from your point of view?

TemplateMonster has become a marketplace now. It features 46,000 pre-designed templates crafted for different types of sites, business niches, and engines including the most popular platforms: WordPress, WooCommerce, Joomla, Magento, Drupal, PrestaShop, and Moto CMS. Our aim is to meet the requirements of as many customers as possible. We offer plenty of cool stuff apart from the ready-made templates. For instance, landing pages, plugins, email templates and many other products. 100k people are visiting the site every day. A team of 427 geeks is working for TemplateMonster. Their joint efforts let TemplateMonster reach $15M in revenue.

Template Monster landing page

Why should web professionals care about companies like TemplateMonster?

Because it’s beneficial for them. Cooperating with TemplateMonster frees their time, speeds their workflow, and lets them earn much more money.

Today all business owners understand how important it is to promote their services/products online. But not every entrepreneur is ready to pay for custom design, hire a developer, and create their online presentation from scratch.

They want to get their website within a reasonable budget, they want it to be quality, to look good, work flawlessly, and don’t wait for ages before their project will go live.

Web design agencies can cater to all these needs if they use our templates.

Tell me about the history of the company and how it was launched.

TemplateMonster was founded in 2002. Can you imagine that: people around the globe used our products when you knew nothing about Facebook and YouTube. We watched the evolution of the web and were proud to contribute into it. Hundreds of thousands websites you see today were built on the basis of our templates.

How everything started… I had been working at a custom design studio then. We tried our best to deliver top-quality products, but, unfortunately, most of our potential customers considered our services too expensive for them.

One day, I saw a designer who used a ready-made template to simplify and speed up his job. That was the moment when an idea to launch TemplateMonster crossed my mind. Eventually, this idea started to turn into a successful business.

Our company has held a leading position in the market for almost 15 years. Of course not all days were fine for us. We survived the rainy ones when something went totally wrong with our products. We got negative testimonials. And the bitter truth is that some of them were true. However, most of them referred to our outdated templates. What did we do? We just removed them from our marketplace.

They say “What doesn’t kill us makes us stronger”. And even negative feedback can be useful. We thoroughly analyzed it and took the right turn. We got deeper understanding of what our customers need, and gave it to them.

Example of a templateMonster template

Thanks for sharing your history. Why should one rely on a template?

Both entrepreneurs with little to no development skills and professional developers use our templates. All our customers get their benefits from our products.

The best thing about templates is that TemplateMonster’s customers see the final result, a ready-made product before paying any money for it.

Templates save time, money, efforts, nerves, whatever, and guarantee satisfaction with the future website.

What are the advantages of this approach instead of coding all by hand (or using Foundation or Bootstrap or other frameworks)?

Entrepreneurs get independence from designers, coders, and other professionals who sometimes overrate their work and don’t meet the deadlines. They don’t need to spend hours and hours searching for a responsible, skillful freelancers who may design something that they may be disappointed with in the end. As I have mentioned above, at TemplateMonster you see the final result at once. In other words, you see a ready-made product you are paying for. All you need to do is just replace the default content with your own.

Suppose you are just getting started and have no idea how to install the template, add your logo and other content, change colors, etc. You think only about the ways to generate more revenues and have no desire to mess with all those things.

So, you want to skip installation, customization or, say, integration with Google Analytics. Then, contact our Service Center. Our trained professionals will take care of everything and deliver you a ready-to-use site within 24 hours. Some tasks are completed even faster, i.e.: we install the template and plugins within 3 hours. There’s no issue members of our Service Center can’t cope with.

As to the coders knowing Bootstrap and other frameworks. Developers who are able to build sites themselves pay money for our products because it is advantageous for them.

With the help of our templates, developers considerably speed up their working process. They deliver more projects and earn more money respectively. We have a vast choice of templates in stock, which means that anyone can find the theme that meets the requirements even of the most picky customers. Creating something from scratch simply makes no sense if our marketplace offers so many ready-made designs. It’s like reinventing the wheel. Smart developers prefer to customize something here and there and deliver the website to the customer as quickly as possible.

I would like to tell you about the project we have launched not so long ago. It gives developers from all over the world an opportunity to get an official certificate from TemplateMonster that proves their skills. They just need to complete a course and then pass a final test (or pass the quiz at once) at our Certification Center. Having a certificate from a globally recognized web design company is a great way to improve your online image and look more credible for the customers.

Besides, having the certificate from TemplateMonster lets you get into Web Studios Catalogue, which gives a heap of additional opportunities.

You raise good points about certification. That is why Web Professionals has been certifying web designers, developers and more for so nearly 20 years.

What are the disadvantages of using a template?

Ok, you caught me;). It’s a tricky question, but I will answer it.

There is an opinion that using a template you fall under the risk to be unoriginal. If you’re going to use a template, then the chances are that you’re not alone, that’s the truth. But what is your chance of seeing a similar website on the Internet among millions of websites if you have bought your template from a marketplace like TemplateMonster with its terrific choice especially after customization? To my mind they are next to nothing. However, if it is crucial for you to be the one and only owner of the design, you can buy it out.

The quality of available templates varies, but in some cases, you might find the choices are rather basic. Some templates rely on you to fill in most of the gaps, and may have a poor set of graphics or visual elements. Frankly speaking I don’t see a big problem here as filling the template with your own content makes your website unique.

Using a template is unchallenging. Relying on templates to put together your projects, means you don’t get the benefits of learning the ins and outs of the software you’re using. But don’t you think that this is the essence of the template – to speed up and simplify the process of website launch? Not all entrepreneurs want to learn to code, design, and so on. They just want to get their benefit from the brand new website asap. A template gives them this possibility. In case they want to study everything that was left behind the scenes, they can sign up for one of our free educational projects (like “Your web studio in 61 days marathon“) and make up leeway.

61 days marathon

Templates are naturally designed to help you get the results as quickly and easily as possible, but in many cases the customization options can be limited, restricting what you can do with your files. That’s why it is important to read the template’s documentation carefully before the purchase. Don’t want to read? Watch the short video from our playlist on YouTube. Don’t want to watch the video or can’t find the relevant one, ask the support manager. They are always available to answer all your questions and help to choose the right template for your purchase. Don’t worry, the guys will work until you are 100% satisfied.

What other products/services do you offer?

2016 became the year when our team focused on developing flagship templates. They are much more multi-faceted compared to our regular products. Let me explain the things with using flagships on the example of WordPress templates. Of course I can’t help mentioning the recent release of Monstroid2 – Multipurpose WordPress Theme. It’s not an ordinary template, it’s a whole toolkit to build an online magazine, business site, personal portfolio, web store, whatever. You can create a complex portal combining several types of sites into one as well. Supposing you want the impossible from a single template: to present your company, plus share some interesting info with clients and sell products at the same time. It’s hard to believe, but using Monstroid2, you can build a business site, add blog and store functionalities to it. Monstroid2 is a one size fits all solution for all the needs you may have.

Here’s how it was. At first we created a flagship for WordPress because it’s the most popular CMS in the world. But then we decided to develop flagships for all popular engines: Joomla, OpenCart, PrestaShop, etc.

But that’s not all, we didn’t forget about the guys who don’t use any CMS at all. You can find new flagships among HTML5 templates. You already know that it’s one of our goals to meet the needs of everyone who comes to TemplateMonster marketplace.

Please note that we don’t charge more for flagship products. You can get any of them for the price of a regular template. Considering professional 24/7 support that we provide for a lifetime, our flagships are the best deals you can find on the market today.

It also should be mentioned that the users can figure out everything by themselves, without professional help. Every template comes well documented. The instructions guide the users through all ins and outs of using it. There are also numerous detailed tutorials at our Help Center and Startup Hub for those of you who are just at the start or want to learn how to handle their template by themselves. What’s more, we run a blog to share a lot of educational content with our audience, particularly, free eBooks, webinars, tips, tools to become more productive, and much more. At TemplateMonster, you won’t just learn how to build beautiful and functional websites lightning-fast, you’ll learn to enjoy the job.

What differentiates you from the competition?

The cost and value of our products comes to my mind first. Our prices are not higher than the ones of our competitors. If you want to save, just search Google and you will always find promo codes to reduce the price by 10%-40%. We always offer great discounts on Christmas, Independence Day, and other public holidays.

Sometimes you find out that the price for this or that template is a bit higher, but, remember about the value we provide. All our customers get more goodies as bonuses to their templates. For example, all our products, except for GPL WordPress themes, are delivered with HD images shown in the demo. It’s a good opportunity to save, as there’s no need to buy stock photos. At TemplateMonster, you can also benefit from free professional technical support.

How long are your templates supported?

TemplateMonster is the only website developer that provides this service for a lifetime without charging any extra payment now. Our competitors provide it for free only for a limited period.

I don’t think it’s fair. Some people don’t use the template straight away. It’s your right to decide when to use the product you paid for. But with a time limit on free support, you’ll have to pay extra money to get consultation, say, in half a year or stay on your own with your issues.

This is not our method. We are ready to help our customers any time at TemplateMonster (the same day, in a week, in a month, in a year, and so on). What’s even more important, our team of experts works until it’s over. Every customer should be absolutely satisfied.

Though, words are not a weighty argument. Thanks to our unsurpassed customer service, we entered the top three of web design companies per the TrustPilot rating. Do you believe this bullet-proof resource with verified customers reviews? So many people can’t be under a delusion.

Here is a video to prove my words.

David, what happens with a purchased template as web technologies continue to evolve?

It’s a good question. You need to update your site regularly and redesign it from time to time if you don’t want to look outdated. Trends are changeable, you’d better not miss the moment when your site starts looking rusty. Customers never take your seriously if your corporate web presentation looks outmoded.

I also recommend you to check how user-friendly your site is in terms of navigation, readability, and other essential aspects. It’s very important to test how it works on smartphones and tablets all of us use to browse the web on the go. Your site must adjust to all modern mobile devices, otherwise you will lose clients. If your site is not mobile-friendly, you can forget about high SEO rankings. Google doesn’t like such kind of sites.
BTW, flagships owners may not worry about the matter. Their websites will serve them for many years to come as regular updates are included into templates packages prices.

Thank you very much, David. You provided lots of thought provoking information for both practicing and aspiring web professionals. Have any more questions for David? Ask them in the comment section below.