Archive for December, 2007

Blackhat Linkbombing To Hurt Your Competitors New Website?

SEO General 10 Comments »
If you're new here, you may want to subscribe to the RSS feed. Thank you for visiting SEMSPot!

Let me start off by saying that I do not condone using this type of technique by any means. This is an article around learning the darker side of search engine marketing, since we do not see many articles related to it. Many people ask about black hat marketing methods and techniques, this can be considered a very black hat method.

As we all know, backlinks are essential in a marketing campaign for any website. The more relevant backlinks you have to your site, the better it is for your SERP’s. So let’s say you have just finished up your new website and are looking to start promoting it to the general public. You could start with simple forum signature links, paid directory submissions to high profile directories such as Best Of The Web, use Yahoo Answer’s by replaying to questions in the same category as your website, or just buy text links. There are several other ways to start building backlinks to your site, but those can be covered in another article. The problem can arise for you if you gain too many backlinks in a short amount of time for your website. Since the website is still new, you do not have many backlinks, if any at all.

To the search engines, you are like a small seed waiting to grow. As you get more backlinks, you are in essence watering your seed (no not that way). If you get to many backlinks to fast, that is like taking a huge bucket of water and pouring it on your little seed. As we all know that too much water is a bad thing, and over watering can kill the growth process. So imagine what would happen if you went out and got hundreds and hundreds of backlinks each day to your new site. Yes you guessed it, you can hurt your new website. The search engines will actually penalize your website if you all of a sudden starting showing all these backlinks very quickly.

watering-links.jpg
Now take the over watering technique and apply that to a competitors new website. The same thing will happen to there site, to many backlinks in a short amount of time and they will get penalized in no time. I do not think that this would work on a well established website since the site has been around for years and has built the authority and backlink numbers already. What good is a few hundred links a day going to do to a site that already has hundreds of thousands?

There are two pieces of software that I can think of that would be able to accomplish this task for you with very little work. Xrumer and Prosubmitter are tools used to auto submit your website URLS to forums, blogs, message boards etc. automatically. These are not your typical run of the mill programs and can seriously harm your site if abused.

xrumer and prosubmitter

Xrumer works with several popular forums, it can auto create the account (breaks almost all security measures, captcha, word text, javascript and even email verification) and post messages for you. Even after you post a message with the URL, it can then go back to the same forum, create another account and post a following up bogus message to your original thread. Yes this software is pretty damn evil, it is multi threaded and can run on proxy servers. There are more in depth features of the program, but this should give you a general idea as to what it does and how it operates. So take either of these two, run them for a week straight on your competitors new website and I bet within a few weeks you will see the penalized results.

I had always thought that the SERP’s could not be manipulated on Google, Yahoo or MSN, but this sure sounds like a way to do it to a new website. So how can you protect your new website from someone who could sabotage it from the start? I am still working on answers to that question so I can share them with all of you. If you have idea’s on how to protect your new website from this sort of attack please post a comment and let everyone know.

This article was originally written and posted on SEMSpot.com, a Search Engine Marketing Blog.

SQL Injection Used To Hack Real Estate Websites (Extreme Blackhat)

Spot On Tuesday 2 Comments »

Spot On Tuesday’s tip of the week is more of a warning then anything else. I felt it was needed to make this exploit public as soon as possible because I do not condone in hacking any website. This method was being used for two things, one to deface the website completely and redirect it to where ever the person intended and secondly this method is being used to add links to the website in an effort to increase the backlinks for whomever. Imagine you find 200 sites, some have a low PR, some have a high PR and you used this method to add as many links as you saw fit to help boost your site. This not only allows you to do that, it also gives you full admin rights to the site and that is why I feel it was needed to bring this out in the open. This exploit revolves around phprealestatescript.com, which they have issued a fix for this known problem as of this posting. If you or anyone you know that uses this script on there website (mainly real estate websites) then please pass this information along to them and have them download the fix for this attack. You can download the patch here from there site. I will show you how this method is used by people, so let’s get started.

Step 1. Do a search on Google for “Browse with Interactive Map” with the quotation marks. This will bring up results like these on the first page.

Real estate websites hacked with sql injection

Step 2. Find a site that has not already been exploited, just go to like page 19 and you will be able to test this method out. If you find sites that are still vulnerable then PLEASE contact them and let them know how to fix it. In the browser simply put in

www.website.com/fullnews.php?id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,char(58),password),4,5/**/FROM/**/admin/*

Of course you will need to change the website.com to whatever the actual site address is. Once entered, if the site has not already been compromised it will bring up a screen like this.

results.jpg

Step 3. As you can see by the image, we now have the admin login information for this website. Now a quick visit to www.sitename.com/admin/login.php and you should see the admin login.

real-estate-login.jpg

With admin access you have rights to the site and can make changes as you see fit. Now imagine a high traffic website that is now running your affiliate ads, or has site links inserted on high profile pages, etc. Yes this is pretty damn evil, but as shown above there are people who are taking down entire sites using this method. I hope you take this serious and update any websites you, friends, clients that use this real estate script for there website. The damage is extreme, a patch has been issued by the script creators so please go and update your’s ASAP!

This article was originally written and posted on SEMSpot.com, a Search Engine Marketing Blog. If you like the article please sign up to our RSS Feed.

Was Shoemoney’s YSM Account The Victim Of Sabotage?

Misc. Comments Off

Shoemoney Fame Get Him Sabotaged?

 

 

So here I am thinking as to why Yahoo would come out and say “It is not your fault, but we have to terminate your account” to Shoemoney. There are several email responses listed on his site in regards to Yahoo Search Marketing - ‘We Know We suck’ in which Michelle tells Jeremy that his account has a 65% fraudulent charge rate, it is not your fault, but we will be terminating your account. What in the hell kind of statement is that? Michelle said that Yahoo could not tie discrete clicks to the fraudulent sign ups. You would think that a company the size of Yahoo would have there stuff in order. I guess I am wrong by thinking this. They cannot keep track of referring URL’s from Commission Junction, they cannot detect the use of that many fraudulent credit cards, and they would not assign him another ID to basically make him a new account. I was surprised by this and to top it all off last summer he was in Yahoo’s top 3 for monthly earnings.

Everyone in the industry knows who Shoemoney is, he has made a name for himself weather you think it is good or bad. So with the fame can come the hater’s, or the people who are either jealous or have a grudge against him. Who is to say you could not hire someone in another country to fraudulently sign up using stolen credit card information. There are forums you can go to and actually purchase these types of services I am sure. As bad as that sounds, it is true. Instead of attacking the person publicly and making a name for your self, they could have just out sourced this sabotage attack on his Yahoo Search Marketing account by signing up using the stolen credit cards. Imagine the damage you could do to so many other big account holders.

The truth is that Yahoo needs to get there shit straight, they know they are falling even further behind Google as to being the dominate search engine. With poor support for there top money makers, a tracking system that cannot fully track referring URL’s and shutting down an account even after they admitted it was not his fault. Wow, what kind of system are you people running over there? That many degrees in one building and you pull a stunt like this? Yahoo you need to get a bigger paddle, because you are falling downstream faster then your arms can move with stunts like this.

I could be wrong but who is to stop someone from “carding” on the Yahoo Network to get other accounts shut down like this. My answer is simple, nobody because Yahoo seems to not have full control over there own system and how it is run. What are your thoughts on that, do you think Shoemoney was a victim of his own success and someone sabotaged his account on purpose? I would love to hear what everyone else thinks.