URL Spoof Issue in Search Results
-
Hello!
We could use some assistance diagnosing an issue. In order to avoid asking a convoluted question, I will try to break it down below:
1. A random foreign site is hacked and a subdirectory is added that is completely irrelevant to the root.
a). i.e. http://www.um.org/prom_dresses/
2. http://www.um.org/prom_dresses/ is just a phishing prom dress page
3. When you search "prom dress shop", the website that used to rank first (for good reason) was www.promdressshop.com.
4. www.promdressshop.com's home page has now been replaced by: um.org/prom_dresses/ – who is using prom dress shop's title tag and meta description.
How is it possible that this hacked page (on um.org) is not only ranking above us, but is also starting to replace www.promdressshop.com's pages in search results. We do not believe www.promdressshop.com has been hacked but are open to any ideas.
Please let me know if you would like any additional info. Thanks in advance!
-
Thank you for your response! We have combed through the code and server activity and there has been nothing changed recently (that we have noticed thus far). However, we will definitely keep you updated.
Thanks!
-
Thank you for the response! We have considered some of these angles but it has been tough to pinpoint the issue. It looks like our spam report took care of it for now but we will keep you guys updated. This is also happening to some competitors so we are all leaning toward this being a serious case of black hat SEO.
Thanks again!
-
Ok, so, my view on this.
In response to livecam's comment, __VIEWSTATE (the code he was refering too) is a base64 encoded form field used in ASP.net to hold data. Its probably not malicous in this instance. see this: http://stackoverflow.com/questions/1350216/what-does-the-viewstate-hold
For me, when i search "prom dress shop" in an incognito chrome window, i dont see either entry on the front page of google, though i expect this is because im searching from the UK.
Reviewing the pages specifically, i can make a couple of suggestions.
- Check your web.conf file, your main domain may have been hacked and this adjusted to send only search engine to um.org (to hide the hack)
- it may be that um.org has used Black Hat SEO technique's to massivly raise its profile, this will be short term as google will slap them with loads of penalties pretty quickly.
- Check your web server specifically for viruses etc. Being an ASP.net site, you'll be hosted on a windows server, running IIS. It will be just as prone to viruses as your windows PC at home (without the proper protection).
If you would like a hand to check your site code specifically, drop me a PM and we can see what we can do. Otherwise, if you have in house developers, they should be able to take a look.
-
Did you check page source codes of promdressshop.com ? When i check (ctrl+u) I see there is a large code structure. Usually this is not normal. This encrypted code and It may be embedded malicious code.
And search engines can be described this code as harmful.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Dates on Google Search Results
Hello, I manage htts://globalrose.com When I search on Google for "Yellow Roses", "Yellow Roses Globalrose", or any search that might bring up one of our pages, sometimes our search results appear with dates right before the description. Does anyone know what this mean? Why they appear on some and not other pages? Here is a search result for example: Example Google Search Can someone please help clarify this for us?
Intermediate & Advanced SEO | | globalrose.com0 -
How would you address these URLS
Hey Mozzers, long time no post. Just a quick one for you regarding URLS, this is an example of a url on a site https://www.thisismyurl.co.uk/products/spacehoppers/special-spacehopper.html Many of these pages are getting flagged for having a url that is too long. The target of this page is "special spacehoppers". Should i be concerned with the url being to long given my keyword is at the end? Would this be a suitable idea? https://www.thisismyurl.co.uk/p/spacehoppers/special.html Would changing products to p be worthwhile? It would remove length from nearly all urls but would require a site wide re-direct. 2)Would removing the "spacehoppers" bit from the url be worth it? Yes it would shorten the url but would also remove the exact keyword from the url which could be detrimental to rankings.
Intermediate & Advanced SEO | | ATP0 -
Google Search Console
abc.com www.com http://abc.com http://www.abc.com https://abc.com https://www.abc.com _ your question in detail. The more information you give, the better! It helps give context for a great answer._
Intermediate & Advanced SEO | | brianvest0 -
Duplicate URLs ending with #!
Hi guys, Does anyone know why a site can contain duplicate URLs ending with hastag & exclamation mark e.g. https://site.com.au/#! We are finding a lot of these URLs (as duplicates) and i was wondering what they are from developer standpoint? And do you think it's worth the time and effort adding a rel canonical tag or 301 to these URLs eventhough they're not getting indexed by Google? Cheers, Chris
Intermediate & Advanced SEO | | jayoliverwright0 -
Image URLs - best practice
Hi - I'm assuming image URL best practice follows same principles as non image URLs (not too many files and so on) - I notice alot of web devs putting photos in subdomains, so wonder if I'm missing something (I usually avoid subdomains like the plague)!
Intermediate & Advanced SEO | | McTaggart1 -
Can you nofollow a URL?
Hey Moz Community, My questions sounds pretty simple but unfortunately, it isn't. I have a domain name (we'll use example.com for this) http://example.com which 301 re-directs to http://www.example.com. http://example.com has bad links pointing to it and http://www.example.com does not. So essentially, I want to stop negative influences from http://example.com being passed on to http://www.example.com. A 302 re-direct sounds like it would work in theory but is this the best way to go about this? Just so you know, we have completed a reconsideration request a long time ago but I think the bad links are still negatively affecting the website as it does not rank for it's own name which is bizarre. Actual Question: How do I re-direct http://example.com to http://www.example.com without passing on the negative SEO attached to http://example.com? Thanks in advance!
Intermediate & Advanced SEO | | RiceMedia0 -
Crawling issue
Hello, I am working on 3 weeks old new Magento website. On GWT, under index status >advanced, I can only see 1 crawl on the 4th day of launching and I don't see any numbers for indexed or blocked status. | Total indexed | Ever crawled | Blocked by robots | Removed |
Intermediate & Advanced SEO | | sedamiran
| 0 | 1 | 0 | 0 | I can see the traffic on Google Analytic and i can see the website on SERPS when i search for some of the keywords, i can see the links appear on Google but i don't see any numbers on GWT.. As far as I check there is no 'no index' or robot block issue but Google doesn't crawl the website for some reason. Any ideas why i cannot see any numbers for indexed or crawled status on GWT? Thanks Seda | | | | |
| | | | |0 -
301 redirect with /? in URL
For a Wordpress site that has the ending / in the URL with a ? after it... how can you do a 301 redirect to strip off anything after the / For example how to take this URL domain.com/article-name/?utm_source=feedburner and 301 to this URL domain.com/article-name/ Thank you for the help
Intermediate & Advanced SEO | | COEDMediaGroup0