Attackers Targeting .Edu Sites in SEO Poisoning Campaigns
Having mastered the art of poisoning search engine results for .com sites, attackers are now turning their attention to .edu sites, linking their keyword campaigns to educational institutions as a way of lending their malicious sites more credence in the eyes of Google.
The goal of these attacks is the same as those targeting commercial sites: to elevate the rank of the malicious sites so that they become more attractive to users searching for information on a given topic. Robert Hansen, a security researcher and CEO of SecTheory, has been investigating the SEO poisoning campaigns, and what he found was not very heartening.
By getting .edu (which ranks higher than .com for instance) to link to a site with the right keywords, Google is tricked into thinking the site is of higher value. Yes, Google’s algorithm really is that simple to get around, which is why there is a lot of garbage in their index now. It just took a while for the bad guys to get a large enough mass of hacked sites.
So I started messing around with search strings that would help me identify highly probably hacked sites and poof - within a few minutes I had dozens upon dozens of high value compromises:
Editor's Pick
inurl:.edu viagra
inurl:.edu cialis
inurl:.edu phentermine
The SEO poisoning campaigns against .com sites have been very successful, with attackers and spammers relying on the technique to draw victims to phishing sites and other undesirable destinations. Such attacks can be very difficult to recognize and avoid, perhaps even more so with the .edu campaign.
Many colleges and research institutions have legitimate connections to some of the keywords that spammers and phishers favor--such as medical and pharmaceutical terms--making it even more problematic for victims.
Commenting on this Article is closed.
Today's Most Popular
- Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit
- New Tool Will Automate Password Cracks on Common SCADA Product
- How Offensive Research Drives Down the Cost of Attacks
- Researchers Dump Trove of 0Days For Popular Android Applications
- Citadel Malware Authors Adopt Open-Source Development Model
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (7)
-
Apple Ships Huge Set of Patches for OS X (7)
-
Privacy Fail: Is Uncle Sam Encouraging Bad Security? (8)
-
Flash With Sandbox in the Works for Firefox (4)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (55)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



