There’s a new threat on the loose targeting websites, where a sophisticated SEO campaign used SQL injections. Affected websites will distribute hidden HTML links the confuse search engine bots and erroneously impact page rankings.
The threat was discovered by Akamai Technologies Threat Research Division.
Over the course of a two week period in Q3 2015, Threat Research analysed data gathered from the Akamai Intelligent Platform and observed attacks on more than 3800 websites and 348 unique IP addresses participating in the various campaigns, revealing the following key findings:
Search engines use specific algorithms to determine page rankings and indexing for sites on the web, and the number and reputation of links that redirect to the web application influence these rankings, Akamai Technologies explains.
According to the company, the SEO attackers created a chain of external links that direct to stories of cheating and infidelity on the web to mimic normal web content and impact search engine algorithms.
“The ability to manipulate page rankings is an enticing proposition and business for attackers,” says Stuart Scholly, senior vice president and general manager, Security Business Unit, Akamai.
“If successful, attacks can impact revenue and, most importantly, the reputation of many organisations and companies using the internet,” he says.
Scholly says attacks in the campaign have demonstrated a unique understanding of search engine operations, and accordingly, Threat Research recommends the following defence techniques:
For Web Application Developers
For Web Application Defenders