Page 1 of 2 1 2 LastLast
Results 1 to 15 of 20

SEO Security Advisory - Check your sites NOW

This is a discussion on SEO Security Advisory - Check your sites NOW within the General Discussion forums, part of the vBSEO SEO Plugin category; This wont apply to vBSEO sites, mbut for those with non-vbulletin sites, you will want to check this out right ...

  1. #1
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times

    SEO Security Advisory - Check your sites NOW

    This wont apply to vBSEO sites, mbut for those with non-vbulletin sites, you will want to check this out right away.

    Full details here.
    SEO Security Advisory - Check your sites NOW
    Rob - SEO Specialist

  2. #2
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    Auckland, New Zealand, New Zealand
    Posts
    4,011
    Liked
    13 times
    Wow!

    That's a pretty serious situation you are describing Rob.

    I will read it again once this cup of coffee has sunken in.

  3. #3
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times
    lets face it ace..... the whole seo world is up in arms over duplicate content.... a simple search on google for 'duplicate content google' will show you how bad and serious the dupe content problem is in the google world.

    Lets say for arguments sake, that vBSEO wasnt as secure as it is... I could link to this thread with a doctored link, with the link text :- vbseo bad security

    like I said, if vBSEO was open to this hole, I would have done two things.... created a duplicate content page on this site, and worse than that - the *potential* for a drastic NEW KIND of googlebomb exists... because the words in the link text ALL EXIST in this page. All you need is many sites linking with the same link text.

    I cannot yet confirm if the googlebomb potential exists, but if you use words in the link text that exist on the page, and then inject those keywords into urls also, then I'm pretty much 95% certain this would get around the googlebomb patches that were put in place by google very recently.

    You bet its bad, thankfully not for vBSEO though.
    Rob - SEO Specialist

  4. #4
    Senior Member Brandon Sheley's Avatar
    Real Name
    Brandon Sheley
    Join Date
    Oct 2005
    Location
    Kansas
    Posts
    2,348
    Liked
    20 times
    Blog Entries
    1
    I don't get how you made a second page with the root url ?

    btw, Great tagline on your site
    My forums: General Forums | Admin Talk (running xenforo)

  5. #5
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times
    heh.. .thanks.

    This is impossible to do for root urls (domain roots), but it's fairly easily possible on as many as 1 in 4 websites for inner pages.

    see if you can spot the similarities in these url's and you will know instantly what I'm getting at

    CommunitySEO for IPB v1.0 Feature List - CommunitySEO
    CommunitySEO for IPB v1.0 Feature List - CommunitySEO
    CommunitySEO for IPB v1.0 Feature List - CommunitySEO
    CommunitySEO for IPB v1.0 Feature List - CommunitySEO

    Hope you understand now.
    Rob - SEO Specialist

  6. #6
    Senior Member Brandon Sheley's Avatar
    Real Name
    Brandon Sheley
    Join Date
    Oct 2005
    Location
    Kansas
    Posts
    2,348
    Liked
    20 times
    Blog Entries
    1
    I understand what your saying..
    I don't see how you made

    notyoursite.com/forums/thread-title-that-you-make.html ?
    My forums: General Forums | Admin Talk (running xenforo)

  7. #7
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    Auckland, New Zealand, New Zealand
    Posts
    4,011
    Liked
    13 times
    Regardless of the CRU content, the "t35.html" remains the same.

    What does that?

  8. #8
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times
    What is it that you can't get?

    Many sites are not careful with ensuring URL integrity... it's that simple.

    Juan.... can you see what i mean here.... lol Is there anyone's head this isn't whizzing over?
    Rob - SEO Specialist

  9. #9
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    Auckland, New Zealand, New Zealand
    Posts
    4,011
    Liked
    13 times
    I get it. Is it only IPB sites that have this 'feature'?

    CommunitySEO for IPB v1.0 Feature List - CommunitySEO

  10. #10
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times
    Hi Ace..... that site was one i truly, and genuinly picked at random. This affects joomla, worldpress, drupal, mambo and many hundreds of other content rewritten applications also.

    It also includes many home-rolled sites that implement url rewriting!

    THIS ISNT JUST FORUMS! ..... it's far more serious.
    Rob - SEO Specialist

  11. #11
    Senior Member Brandon Sheley's Avatar
    Real Name
    Brandon Sheley
    Join Date
    Oct 2005
    Location
    Kansas
    Posts
    2,348
    Liked
    20 times
    Blog Entries
    1
    I don't see how you can make a URL on a site that isn't yours.... ?
    My forums: General Forums | Admin Talk (running xenforo)

  12. #12
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    Auckland, New Zealand, New Zealand
    Posts
    4,011
    Liked
    13 times
    It's to do with the way the 'target' site has its rewrite set up.

    With the one that has been used as an example in this thread, *anything*t35.html will show that page.

    Therefore, all we need is another site that we use to send spiders to that site, using different URLs. Dupe content applies, and they take a hit.

  13. #13
    Senior Member
    Real Name
    Joseph Ward
    Join Date
    Jun 2005
    Posts
    23,845
    Liked
    36 times
    Blog Entries
    9
    We would auto-301 anything like that, but I understand that it is a cause for concern especially for other types of rewritten CMS.

  14. #14
    Senior Member Brandon Sheley's Avatar
    Real Name
    Brandon Sheley
    Join Date
    Oct 2005
    Location
    Kansas
    Posts
    2,348
    Liked
    20 times
    Blog Entries
    1
    wow

    CommunitySEO for IPB v1.0 Feature List - CommunitySEO

    how odd, this is for all sites ? does it work with the htaccess ? like can it be done to my blog vBulletin Setup ? :(
    My forums: General Forums | Admin Talk (running xenforo)

  15. #15
    rob
    rob is offline
    Senior Member rob's Avatar
    Real Name
    Rob
    Join Date
    Oct 2005
    Location
    Eastbourne, UK
    Posts
    982
    Liked
    2 times
    Your site is safe to a certain degree (in the fact you cant inject keywords into the url), but you can still add lots of dupe content....
    eg:
    vBulletin Setup » Blog Archive » Do you want to Earn money posting on vBulletinSetup ?

    Prolly an easy fix - you are replacing hypens with spaces and using trim....
    just dont use trim
    Rob - SEO Specialist

Page 1 of 2 1 2 LastLast

Similar Threads

  1. SEO Software
    By Joe Ward in forum General Discussion
    Replies: 33
    Last Post: 10-28-2011, 03:15 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •