Firms use evil SEO to kill rivals' Google rankings

By Liam Tung, ZDNet Australia
Tuesday, April 08, 2008 11:02 AM

Competition for dominance of search engine rankings is turning sour as rival companies sabotage each other's Web sites to trick search engines into mistakenly believing them to be spam sites.

Rivals are undermining each others search engine optimization efforts by exploiting cross-site scripting (XSS) and SQL-injection Web site vulnerabilities to fool search engines into categorizing them as malicious.

XSS and SQL-injections flaws have typically been used to create phishing scams or drive-by-download attacks that use malware to take control of a Web site visitor's machine.

However, in this case, the techniques can be used to destroy the visibility of a competitor through Google.

By exploiting flaws, such as using a Web feedback field to enter malicious code on a targeted Web site, an attacker is able to make the target site appear as if it were attempting to improve its rankings by forcing its own URL onto other Web sites.

"We are talking about including injecting spam links to a target site through cross-site scripting," Security-Assessment.com security researcher Roberto Suggi Liverani told ITradio.com.au.

"The attacker might use social bookmarks like Digg.com or Reddit.com… and can actually simulate persons with multiple accounts using the same IP address and spamming the URL of the target site. This makes it appear as if the site is self-promoting," he said.

The type of attack relies on the interdependent trust system that search engines use to rank Web sites, according to Liverani.

To mitigate the threat, Liverani said: "Always follow what's happening on your site... You can use the Google Webmaster tools, which are a way to communicate with the search engine."

The full interview with Roberto Suggi Liverani can be heard here.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary - part three: Topic intention comparisons

Web Development

Justin James chronicles his process of using Hapax's OpenAmplify Web service to create an application that can match documents with content that is similar or identical to the source document.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




What Y2K can teach us about 2012

Blog thumbnail

Dec. 21, 2012. It's a big day on the calendar, particularly because some believe it marks the last day of the world as we know it. The apocalypse. Armageddon.

The..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web