Firms use evil SEO to kill rivals' Google rankings

By Liam Tung, ZDNet Australia
Tuesday, April 08, 2008 11:02 AM

Competition for dominance of search engine rankings is turning sour as rival companies sabotage each other's Web sites to trick search engines into mistakenly believing them to be spam sites.

Rivals are undermining each others search engine optimization efforts by exploiting cross-site scripting (XSS) and SQL-injection Web site vulnerabilities to fool search engines into categorizing them as malicious.

XSS and SQL-injections flaws have typically been used to create phishing scams or drive-by-download attacks that use malware to take control of a Web site visitor's machine.

However, in this case, the techniques can be used to destroy the visibility of a competitor through Google.

By exploiting flaws, such as using a Web feedback field to enter malicious code on a targeted Web site, an attacker is able to make the target site appear as if it were attempting to improve its rankings by forcing its own URL onto other Web sites.

"We are talking about including injecting spam links to a target site through cross-site scripting," Security-Assessment.com security researcher Roberto Suggi Liverani told ITradio.com.au.

"The attacker might use social bookmarks like Digg.com or Reddit.com… and can actually simulate persons with multiple accounts using the same IP address and spamming the URL of the target site. This makes it appear as if the site is self-promoting," he said.

The type of attack relies on the interdependent trust system that search engines use to rank Web sites, according to Liverani.

To mitigate the threat, Liverani said: "Always follow what's happening on your site... You can use the Google Webmaster tools, which are a way to communicate with the search engine."

The full interview with Roberto Suggi Liverani can be heard here.


See also:  Web sites, Search
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Secure ASP.NET sites with Membership API

Web Development

Beginning with ASP.NET 2.0, the Membership API was added to simplify adding security to a Web application. Find out how to use the Membership API with a SQL Server backend.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attacks
  3. botnet
  4. credit
  5. data
  6. details
  7. dns
  8. e-mail
  9. facebook
  10. fix
  11. flaw
  12. flaws
  13. fraud
  14. google
  15. iphone
  16. issues
  17. microsoft
  18. over
  19. oyster
  20. patch
  21. releases
  22. researcher
  23. researchers
  24. security
  25. storm
  26. team
  27. uk
  28. us
  29. warns
  30. worm

ZDNet Asia Top Tech 50 to recognize Asia's potential

Blog thumbnail

The ZDNet Asia Top Tech 50 awards are back, and we're once again seeking nominations to identify the industry's best-performing tech companies.

The marketplace is crowded with players clamoring for..... by Eileen Yu

Read more »