Site under attack from Android SEO bots - expert help needed
-
For last 25 days, we are facing a weird attack on our site.
We are getting 10x the normal mobile traffic - all from Android, searching for our name specifically. We are sure that this is not authentic traffic as the traffic is coming from Organic searches and bouncing off. Initially, we thought this was a DDoS attack, but that does not seem to be the case.
It looks like someone is trying to damage our Google reputation by performing too many searches and bouncing off.
Has any one else faced a similar issue before? What can be done to mitigate the impact on site.
(FYI - we get ~2M visits month on month, 80% from Google organic searches). Any help would be highly appreciated.
-
Just as EGOL describe it.
If you're on Amazon AWS then you can use their CloudFront as CDN. But also you can observe source of traffic. Could coming from one country, one IP range or one user-agent. There should be some kind of pattern and you should investigate it.
Then just need to make rule to block that traffic or just redirect them to one static "hello world" page.
I was also victim of such traffic, but was from humans trying to depleting an AdWords daily budget. Once budget it over ads was stopped showing, after few hours they recalculate clicks, some funds was returned, ads are shown again, they click it, budget is over... and so on.
-
By resetting your DNS to CF, your server is no longer used. All traffic is routed to one of CF's data centers and there are over 100 of them distributed throughout the world.
Also, in the CF settings, you want to "challenge" the visitors from problem countries. This will give them a captcha to complete. When they complete that captcha one time, you can then give them long term access without the challenge. CF will progressively become better at filtering the bots and allowing more trusted visitors in without a challenge.
-
Thanks for your help - this works to a large degree.
Have hit a new challenge though, our AWS servers are in one of these countries which are sending traffic. And we have multiple servers talking to each other enabling Login / other actions on the site.
While I have blocked all the other countries, blocking country with AWS servers is creating problem with Login. Trying to figure this out!
-
If you don't use Firewall, Cloudflare in your situation will have almost no effect.
We used our analytics to determine the countries where the traffic was coming from. Then went into CF FW.
Click the blue Help link for each tool to decide upon the settings that you want to try.
Here is what we used....
Security Level... Medium
Challenge Passage... one day
Access rules.... country name, challenge, this website
Impact of the above.... Many bots already recognized by CF will be blocked. Access rules will present each visitor from those countries a form similar to a captcha. They must pass the captcha to get in.
After you turn this on, watch your short term stats. You should see an increase in blocking.
We ran the above for a few weeks without any obvious SEO impact. Then switched our DNS back to normal, moving away from CF.... but kept the $20/month account and our settings in place. CF was time-consuming to set up.
-
This looks very similar to what we are seeing. We took CloudFlare as well - but stayed with Free account with "Site Under Attack" mode, which should force the visits to verify.
Will it be possible for you to share the settings on CloudFlare? Did you use their Firewall as well? Also, did you see any SEO impact, by any chance?
-
One morning, a few months ago we saw lots of mobile phone traffic building. All was hitting our homepage which is very resource intensive. All of this traffic generated one page view. All of the traffic was coming from a few countries in Asia and Africa. No referrer. Looked like a DDOS attack.
We go to Cloudflare, got a $20/month account, switched DNS to CF, forced untrusted visits from those countries to verify before allowing entry. Squeezed this traffic down to almost nothing within a few hours. Left CF run for a few weeks. Rouge traffic disappeared.
Now we have CF ready to go with all settings in place. Can turn it on in two minutes and have the shield in place as DNS propagates.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
SEO benefits/drawbacks of physical address on site.
Simple question - how much of an SEO impact does NOT having a physical address on your site make? I run a photography business based from home. For security reasons I don't really want our home address easily available to the public. I have a Google Maps listing (actually seem to have two at the moment, but that's a different matter) and the full address is logged there but is not viewable publicly - just the surrounding area. Any thoughts would be appreciated.
Intermediate & Advanced SEO | | robandsarahgillespie0 -
Moving to a new site while keeping old site live
For reasons I won't get into here, I need to move most of my site to a new domain (DOMAIN B) while keeping every single current detail on the old domain (DOMAIN A) as it is. Meaning, there will be 2 live websites that have mostly the same content, but I want the content to appear to search engines as though it now belongs to DOMAIN B. Weird situation. I know. I've run around in circles trying to figure out the best course of action. What do you think is the best way of going about this? Do I simply point DOMAIN A's canonical tags to the copied content on DOMAIN B and call it good? Should I ask sites that link to DOMAIN A to change their links to DOMAIN B, or start fresh and cut my losses? Should I still file a change of address with GWT, even though I'm not going to 301 redirect anything?
Intermediate & Advanced SEO | | kdaniels0 -
New site causes massive drop off in ranking, old site restored how long to recover?
Hello, We launched and updated version of our site, mainly design changes and some functionality. 3 days after the launch we vanished from the rankings, previous page one results were now out of the top 100. We have identified some of the issues with the new site and chose to restore the old well ranking site. My question is how long might it take for the ranking to come back, if at all? The drop happened on the third day and the site was restored on the third day. We are now on day 6. Using GWT with have used fetch as Google and resubmitted the site map. Any help would be gladly received. Thanks James
Intermediate & Advanced SEO | | JamesBryant0 -
Should I just redirect all my sites to my main site.
Hi, Over the last few years I have built many sites and own a lot of domain names. Some have high page rank some have high domain authority and some have many back links. I'm finding it very difficult to keep up with all the links and being able to provide quality content for everything. Should I just redirect everything to my one site that make the most money as all sites are for the same industry, but in different categories of that industry. So I could 301 redirect all the sites to the relevant page on my money site. Would it be a problem is 1000's if not 10,000's of links all of a sudden pointed in to one site?
Intermediate & Advanced SEO | | cibble030 -
Are Their Any SEO Dangers When Cleaning Up a Site
I'm doing some housekeeping on my website. Removing old blogs that are out of date (2008) or things have moved on. The blogs I'm removing are being 301'd to relevant newer blogs. Can this type of clean up cause any problems that affect the optimisation of a site? Looking forward to hearing your views. Christina
Intermediate & Advanced SEO | | ChristinaRadisic0 -
Need Help Finding Directories to Submit To
I am looking for a lot of free "do follow" technology directories to submit to. Does anyone know of a good directory or a list of some sort of technology directories or something similar? Actually, I guess any directory that has a technology category would be helpful.
Intermediate & Advanced SEO | | MyNet0 -
Preparing a DotNetNuke Active Forums site for SEO push
I'm in the process of buying and running an existing forum that is running on DotNetNuke 5.2.0 and Active Fours 4.1. As part of the transfer, I'm asking that the site be upgraded to the latest version of DNN and AF 4.3. AF 4.3 has SEO-friendly URLs instead of the current long, ugly default URLs, and I'm looking forward to implementing that feature. My specific question is: What would you do to prepare for this upgrade in terms of the content, especially related to the URL changes? I've gone into Google Analytics and downloaded content by page title, exported the first 1000 results, and put those titles into Word and corrected spelling errors in the title so URLs will be based on correct spellings. General background: The site is not currently monetized, and there will not be an initial focus on monetization and likely only smaller efforts (affiliate Amazon links in a resource section) in the future. The site is free for users. I'm fine with taking a hit in organic traffic in the short term. About 1/3 of the traffic is from search engines right now, and less than 30% of the visitors are new visits. The site is going to continue much the same as it has until now. Same moderators, same purpose, same skin, etc. I have access to GA, site is verified in GWT, need to verify in Bing, and I do have root access to the server. I've already started working on image file sizes, both of user-submitted images and site-related images like the header. Until now, I have no experience with DNN or AF or any of the extensions (and am appalled at the price and lack of features of some of those extensions, compared to what I'm used to for WordPress). More general questions: In terms of SEO, I'm intending to treat the upgrade of the forum with the friendly URLs as a re-launch. I'm wanting good URLs, put in a site map, fix non-www to www, etc. When I start making the changes and submitting the site map and generally drawing Google's attention, I want Google to like what it sees, and have as much optimized as possible when googlebot comes around. My goal is to draw more targeted visitors from search that are interested in the content in the site. What other suggestions do you have for the site prep, both from being a forum in general and specifically on DNN/AF? I'm not putting the URL out just yet, as we haven't announced to the users the change of ownership is taking place. Thanks everyone!
Intermediate & Advanced SEO | | KeriMorgret1