John Andrews is a Competitive Webmaster and Search Engine Optimization Consultant in Seattle, Washington. This is John Andrews blog on issues of interest to the SEO community and competitive webmasters. Want to know more?

johnon.com  Competitive Webmastering & SEO
July 9th, 2006 by john andrews

How easy is Black Hat SEO?

Let’s say you learn of a Drupal security flaw. Let’s say it permits an unauthorized SQL injection. Let’s say you figure out how to insert a backlink into the Drupal link list using that exploit.

Drupal is a popular Open Source content management system, in use on hundreds of thousands of websites. Itis very good, and very flexible. It is free, but installation and configuration (customization) may cost a few thousdand dollars in consulting fees. Basically, it is free of licensing fees but a real, commercially used product.

So you go to Google, and search “password and instructions will be sent to this e-mail address, so make”, and you find a list of 167,000 URLs of Druapl sites. Then you hit each of the first 1000 of those with your exploit URL .. one at a time… from a free or cheap web hosting account. And then you hit a different Google datacenter for another 1,000 sites.

Or, you could have narrowed your search for on-theme websites (more valuable back links?) by adding a keyword to that Google search such as “seo”. That way you only get the best sites for your back link spam.

How long do you have to act on one of these newly-discovered security vulnerabilities? Many months, as many of the webmasters do not patch or update their Drupal installations once they are deployed. I can’t blame them too much, because once you have customized the installation there is often plenty of work required following any update process.

Often a patch can easily be applied directly to only that part of the Drupal system that was flawed. However, application developers who deploy Drupal for their clients don’t often see direct patching as economically beneficial to them, so they may try and bundle the patch in with some other unfinished (and billable) work for the client. No sale, no patch. In fact, many clients don’t even know they are running Drupal. They paid a consultant for a CMS, and got one that worked.

Spam is not rocket science. Consequently, spamming can be stopped by some simple (albeit tedious) attention to detail. Usually, we are too lazy. Do we therefore deserve to be spammed?

★★ Click to Share!    Digg this     Create a del.icio.us Bookmark     Add to Newsvine
July 7th, 2006 by john andrews

Stealth Link Building via Open Source Contributions

As I waited the two or three minutes Wordpress2 needs to post a small edit to this blog, I wondered why I was so casual about ripping backlinks out of the WordPress templates I downloaded yesterday. That issue is blog-worthy, I think. So this time, I smartly opened a second tab before hitting “save”. So while WordPress takes another 2-3 minutes to update the post slug, I can blog about stealth links in open source software.

I’ll go back and flesh out the issue later, but let’s just say there are plenty of direct backlinks hidden inside these “free” downloads. Some time ago I helped expose a case of user agent cloaking hidden within a front end re-write ruleset for the Invision Power Board forum. In that case, the author had inserted a cloaking script into the front end of a mod designed to make Invision’s forum “search engine friendly”. It quietly inserted 5 or 6 backlinks to his own pop culture websites, so only the search engines would see them. Nasty. We got him to fix it, though.

Now WordPress2 comes with a ton of themes. Each one is a set of code files, and each enjoys ample opportunity to insert backlinks. I always go and remove sitewide footer links because they are clearly not justified (except perhaps with a nofollow…haha) but this time I found myself stripping out several aditional links buried in the code. Some were in sections marked “do not edit anything here”. Some threatened “if you touch anything here, don’t even think of asking for support”. That’s fair enough, but disclosure would be much more…. ethical?

Yawn. Maybe I will start digging and see just how many free hidden backlinks are working for these people. And how many disclose, how many seem to hide the links, or gasp… maybe some or encoded? A task for a rainy day?

Alex King has promoted WordPress themes on his site for years, and gets many submissions. From this post I see some have computer virus/worms embedded, and others have hidden links. I’m not sure what the review process is today.

★★ Click to Share!    Digg this     Create a del.icio.us Bookmark     Add to Newsvine

Competitive Webmaster
More related:

Wonder how to be more competitive at some aspect of the web? Submit your thoughts.

SEO Secret

Not Post Secret

Click HERE



about


John Andrews is a mobile web professional and competitive search engine optimzer (SEO). He's been quietly earning top rank for websites since 1997. About John

navigation

blogroll

categories

comments policy

archives

credits

Recent Posts: ★ Amtrak “Creative Class” and High Speed Rail ★ Google’s Legacy - the Internet Cesspool ★ With the Proper Resources…. ★ Ignorance is Powerful ★ Pay No Attention to the Little Man Behind the Curtain… ★ Google Closure.. will you register your code with the Borg? ★ The Federal Website is the New Sacred Cow ★ Not All Domainers are Scammers ★ Upgrade Mandriva 2009 to Mandriva 2010 : How to Upgrade ★ Purpose Inc. Annual Pubcon Poker Tourney 2009 ★ Evaluating Web Marketing Tools ★ Google buys Twitter for $6 Billion ★ Would you use a Link Building Tool owned by a Link Builder? ★ Google Crowdsourcing 3D Maps ★ Keas.com - another bad domain name ★ New FTC Guidelines ★ Always Be Link Building ★ Rocky Mountain Bank Security ★ The Value of Gestalt ★ Google Sidewiki: A New Marketplace for Trust ★ Meta Tags and SEO for Google ★ Proctor and Gamble Eats Values for Lunch ★ But First, to Prevent Spam, what is 6 plus 4? ★ Domino’s Pizza Delivers SEO ★ Google Owns Your Internets 

Subscribe

☆ about

John Andrews is a mobile web professional and competitive search engine optimzer (SEO). He's been quietly earning top rank for websites since 1997. About John

☆ navigation

  • John Andrews and Competitive Webmastering
  • E-mail Contact Form
  • What does Creativity have to do with SEO?
  • How to Kill Someone Else's AdSense Account: 10 Steps
  • Invitation to Twitter Followers
  • ...unrelated: another good movie "Clean" with Maggie Cheung
  • ...unrelated: My Hundred Dollar Mouse
  • Competitive Thinking
  • Free SEO for NYPHP PHP Talk Members
  • Smart People
  • Disclosure Statement
  • Google Sponsored SPAM
  • Blog Post ideas
  • X-Cart SEO: How to SEO the X Cart Shopping Cart
  • IncrediBill.blogspot.com
  • the nastiest bloke in seo
  • Seattle Domainers Conference
  • Import large file into MySQL : use SOURCE command
  • Vanetine's Day Gift Ideas: Chocolate Fragrance!
  • SEM Rush Keyword Research
  • ☆ blogroll

  • Bellingham SEO
  • cameron olthuis
  • Domain Name Consultant
  • Eu, in Northern France
  • Hans Cave Diving in Mexico
  • Healthcare Search Marketing
  • John Andrews
  • John Andrews SEO
  • Marie Francoise Gaouyer website
  • Mixminion
  • PrivateBloggingWiki
  • Privoxy
  • SEMPDX Interview
  • SEO Quiz
  • SEO Trophy Phrases
  • SMX Search Marketing Expo
  • T.R.A.F.F.I.C. East 2007
  • TOR
  • ☆ categories

    Competition (38)
    Competitive Intelligence (15)
    Competitive Webmastering (486)
    Webmasters to Watch (4)
    domainers (59)
    Oprah (1)
    photography (3)
    Privacy (15)
    Public Relations (180)
    SEO (355)
    Client vs. SEO (2)
    Link Building (2)
    Search Engines vs. SEO (1)
    SEO SECRETS (9)
    SEO vs. SEO (1)
    ThreadWatch Watching (5)
    Silliness (23)
    Social Media (2)
    society (21)
    Uncategorized (22)

    ☆ archives

  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006