Technology Review - Published By MIT
Advertisement

Search Spammers Hacking More Websites

The head of Google's Web-spam-fighting team warns that spammers are increasingly attacking websites.

By Kristina Grifantini

Thursday, July 30, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

The head of Google's Web-spam-fighting team, Matt Cutts, warned last week that spammers are increasingly hacking poorly secured websites in order to "game" search-engine results. At a conference on information retrieval, held in Boston, Cutts also discussed how Google deals with the growing problem of search spam.

Credit: Technology Review

Search spammers try to gain unfair prominence for their Web pages in search results, thereby making money from the products that these sites offer or from advertising posted on them. The practice, also known as "spamdexing," exploits the way search engines' algorithms figure out how to rank different pages for a particular search query. Google's page-rank algorithm, for instance, in part gives prominence to pages that are heavily linked to other material on the Web. Spammers can exploit this by adding links to their site on message boards and forums and by creating fake Web pages filled with these links. Garth Bruen, creator of the Knujon software that keeps track of reported search spam, says that some campaigns involve creating up to 10,000 unique domain names.

"We're getting better at spotting spammy pages," said Cutts after his talk, adding that spammers are increasingly hacking legitimate websites and filling their pages with spam links or redirecting users to other sites.

"As operating systems become more secure and users become savvier in protecting their home machines, I would expect the hacking to shift to poorly secured Web servers," said Cutts. He expects "that trend to continue until webmasters and website owners take precautions to secure Web-server software as well."

"I've talked to some spammers who have large databases of websites with security holes," Cutts said. "You definitely see more Web pages getting linked from hacked sites these days. The trend has been going on for at least a year or so, and I do believe we'll see more of this."

Story continues below

Bruen agrees. "We've seen an increase in spam e-mail and spam domains that not only sell illicit products, but that attempt to download malware and infect the visitor's PC," he says. Such malware could use an unknowing victim's computer to send out e-mail spam.

"It really is an arms race," says Daniel Tunkelang, one of the conference organizers and the chief scientist at search company Endeca.

Comments

  • Honeypot
    I noticed that an anti-spam webpage had three addresses written in white text against a white background. They would be invisible to the eye but perfectly apparent to a bot.
    I sent an email to one of the addresses and got an 'undeliverable' reply. I'm waiting for further results.
    Rate this comment: 12345

    Phineas
    07/30/2009
    Posts:85
    Avg Rating:
    4/5
  • Happened to us
    We think they got in through a SQL database. Had thousands of link pages hidden on the site - porn and selling drugs (probably counterfeit). We'd find and delete them, then they'd pop up in another directory in even larger numbers. We played a cat and mouse game for months trying to track them down. Until we killed the SQL database, they would find every new password. The even spoofed our home page and after one clean-up filled my inbox with over 1,100 emails from a online form. Had to move the site, delete the database and kill all the forms to defeat them.
    Rate this comment: 12345

    fiberman
    07/30/2009
    Posts:73
    Avg Rating:
    3/5
  • thanks for the coverage!
    As I found out from doing my homework after the talk, Google (and Matt specifically) has talked publicly about Google's ability to parse / execute JavaScript--I commented about it in my blog post at The Noisy Channel about his presentation at the SIGIR 2009 Industry Track. But I am curious how robustly they do it. The research on random self-reducibility suggests that the spammers have an advantage in this arms race.
    Rate this comment: 12345

    Daniel Tunke...
    07/30/2009
    Posts:5
    Avg Rating:
    4/5
  • spammers hacking websites...
    google guys should know this too well.
    blogspot is a prime conduit for most of the spammers re-direct urls.
    Rate this comment: 12345

    rcherukuri
    08/01/2009
    Posts:1
    Avg Rating:
    5/5
  • Money
    Capitalism make people do everything to gain more and more money.
    Rate this comment: 12345

    EllenLee
    08/04/2009
    Posts:5
    Avg Rating:
    2/5

Log In

Forgot your password?     Register »
Advertisement
Advertisement
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.