Bogus Search Results
-
Hi,
A website I look after was hacked. We cleaned it up , removed malicious content and changed passwords. However the bogus links which were created have kept multiplying. Search Console is all clear. But they keep adding to Google, bogus links.
My client site is www.mechfieldfm.com.au
For example http://mechfieldfm.com.au/JCB-BACKHOE-IGNITION-SWITCH-WITH-2-KEYS-PART-NO-70180184-70145500-372796/
There are thousands of bogus links created. But I believe they are outside the hosting.
Any help would be appreciated.
-
Thanks for your follow up.
Regards
Wayne
-
These invasive URL hacks can be very tricky to get under control. Sometimes if you're lucky, it's just a matter of erasing the pages and stuff. In other circumstances scripts are injected which recreate the bad URLs (and links to them) when you take them down. You certainly want to be on the lookout for unknown scripts on your site, or links to external scripts which didn't exist before
-
Thanks very much for your detailed response.
When the website was hacked they created the hacked pages and when you searched in Google you would go to an actual page. Once we shut the attack down, the links went back to our website.
I thought I had it under control. Listed in search console not to to index links and was going to place redirects on. But in the last few days another 5 pages of the bogus links have been created. Just checked again and more bogus links are being created. Therefore it could be an endless job, if they are going to be added to.
Correct client is a Air Conditioning service business. When you go to site:mechfieldfm.com.au the first couple of pages are actually from client website.
I will look at locking down the HTTP>HTTPS redirect.
-
Are you sure that this:
http://mechfieldfm.com.au/JCB-BACKHOE-IGNITION-SWITCH-WITH-2-KEYS-PART-NO-70180184-70145500-372796/... is an example of a bogus or hacked page? Because when I check Google's cache for the URL:
https://d.pr/i/6sioLy.png (screenshot)
It looks like it was once a 'real' page. Google's cached version only looks so messed up as they failed to capture the CSS properly. It just seems weird that someone would hack your client's site and just leave info for construction-related products on your client's domain. Usually with hacks it's a phishing / political agenda or something like that (or some kind of scam)
Still, having said that; although your client is in construction they don't seem to list any products of any kind (your client appears to be service-based). You have to admit though, to an outsider, it looks more like 'dev-gone-wrong' than a hack. It's just really weird, at the very least
Can't you just write a redirect rule that 301s or 302s all of those bogus URLs somewhere else? Those URLs shouldn't be accessible anyway. Your client has a valid SSL certificate and the site loads just fine on HTTPS: https://mechfieldfm.com.au - so another question is, why was HTTP left exposed? The bogus URLs are on HTTP, maybe they found an entry-point because that architecture was left exposed instead of being properly redirected
Even Google mostly link to the site on HTTPS:
https://www.google.co.uk/search?q=site%3Amechfieldfm.com.au
https://d.pr/i/XfbNF7.png (screenshot)
Where they're not doing this, it's because they are linking to more examples of 'bogus' URLs. Personally I'd just slap no-index tags and status code 410 (gone) on all of those problematic URLs. If you're worried you can't use no-index as the HTML of those pages is gone, you can still fire Meta no-index directives through the HTTP header using X-Robots, so be sure to look that up
It will probably take a while (some weeks) for Google to digest all the disruption and fixes. In the future, ensure that disused architectures (like HTTP) are made physically inaccessible via redirects. Leaving old architectures active is a recipe for disaster. Once this is all cleaned up, be sure to properly implement HTTP -> HTTPS redirects
Here's something odd. On your client's homepage, the HTTP->HTTPS redirect is properly implemented. Somehow these 'hacked' URLs are evading that redirect. You need to at least lock that down or it could happen again
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
My keywords have low search volume - is it still worth starting a blog?
I'm thinking of starting a new blog, but when I did my keyword research I found that my keywords all have low search volume (under 100 searches per month, with the occasional keyword having 480 searches a month). Is this a deal breaker? Any recommendations would be great - thanks everyone!
Content Development | | Trevorneo1 -
Can someone PLEASE help me find a solution to use a custom search engine for iPhones?? Thanks in advance!
Hey mozzers, I'm in quite the pickle today and would really appreciate some help! i need a way to have my members set their default custom search engine on their iPhones and androids to our sites search engine. Google chrome does on desktops but not iPhones. Thanks for your time/help, Tyler Abernethy
Content Development | | TylerAbernethy0 -
Google Image Search - How to rank?
Hi, How would you optimise for rank higher in image search? Any tips/rules which need to be applied. Thanks.
Content Development | | Bondara0 -
When Search for Blog Guest and to Post, What is the FIRST Metric to lookk at???
I have a online store selling furnace filters. For link building, I started to post on guest blogs I'm new to posting on guest blog and I would like to know what are the most important metrics to look at when selecting a blog? The P.A. ??? I did a few test and this is what I did: in the Goolge-BLOG tab option search for K.W like: ''furnace filters'' ''air furnace filters'' Look at Google results and (MozBar is installed on browser) slect blog with P.A. of 15 or higher Read the post and if I have a relevant content to add, post on the blog and had my infos, store url... Then I keep the blog URL and see if my post get approve and publish. Thank you, BigBlaze
Content Development | | BigBlaze2050 -
Why is an old meta description displaying in search results?
We launched a new version of our retail website in Dec. 2012. This included new content and new metadata. When our homepage displays in search results, it almost always displays with designated meta description - except when it's searched with the .com. In that case, an old version of our meta description (pre-Dec. 2012) is visible, though our current title displays. The old metadata isn't loaded anywhere in our content management system. What can we do to change this?
Content Development | | bcbsm0 -
What is the best way to rank organically for location search?
I just read this great article about location search. I am going o read it over and over again, but I wanted to ask... When ranking organically for location searches, do you recommend posting articles (such as testimonials, etc) or build informative pages - that can link through the home page through the nav bar or through a drop down or what have you. There are so many ways to do it, what do you think is best?
Content Development | | SwanJob0 -
Where is microdata (schema.org) already being used by major search engines?
I know Google recently launched their recipes search, but apart from this where else are you seeing microdata being used?
Content Development | | nicole.healthline0 -
I have a page where you can download a PDF of the material - should I exclude the PDF from the search engines?
In my niche, there is a controversial research article that is very popular. I am writing a rebuttal to this article and giving another point of view. My article has the potential to be really good link bait for my site. The original article is often printed out to be shown to professionals in my niche. My hope is that people will do the same with mine. So, I plan to have a PDF version of my article available on my page. The article that is visible on my site (i.e. non PDF) will be a graphic rich article that is easy for the reader to go through. I plan to have the PDF have all of the same text, but it won't have as many graphics - it will look more like a scientific research article. So, should I exclude the pdf from search engines so that it isn't duplicate content? Or does that even matter seeing as it is a duplicate of my own content? I want people to link to the main article, not the pdf. Any tips would be greatly appreciated!
Content Development | | MarieHaynes1