Tracking Down Rogue Spam Links
-
In Feb, 2015 www.mommyupgrade.com site received the following notification in GWT:
http://www.mommyupgrade.com/: Suspected hackingFeb 4, 2015
Google has detected that some of your pages may contain hidden text or cloaking, techniques that are outside our Webmaster Guidelines.
Specifically, we detected that your site may have been modified by a third party. Typically, the offending party gains access to an insecure directory that has open permissions. Many times, they will upload files or modify existing ones, which then show up as spam in our index.
Sample URLs:At that time, the site was checked by the host and site owner and any suspicious links removed. We thought the problem was resolved until a MOZ crawl on March 22 which highlighted a number of hack links again.This is the link format: http://www.mommyupgrade.com/?p=online-slots
All are related to gambling, casinos and slots.
To find the links, we downloaded the MOZ crawl report and found that all the links were referred from this page: http://www.mommyupgrade.com/how-to-make-rainbow-lollipop-cookies/
Searching that post shows no sign of links to the rogue pages.
I would really appreciate some advice on how to find the source of these links and delete them from this site once and for all. Also, please explain how it is possible for a post or page to refer to another page without that link showing up in the code? (Is this some black hat technique that I need to know about in order to protect my sites?)
Also... at the moment Google Webmaster Tools are not reporting any security issues for this site.
Any help appreciated.
-
You're welcome. I'm always amazed at the diversity of people that read and comment here. A lot of talented eyes are considering the questions for sure. Cheers!
-
@Ryan, that link is very useful and once we have the site clean we can use it regularly to check that no new issues presnt themselves.
@Richard, thank you for this information. It helps a lot.
Great community support. I wish I had asked this question days ago.Thank you MOZ.
-
There are some base 64 encoded URLs on the page. They show in the source code like below. That would be my guess as to what is creating the links, which are obfuscated for users. These types of attacks are usually called in your functions.php file or within a hacked plugin, or could actually be inserted into the css as well.
background:url(data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGgAAABoCAYAAAAdHLWhAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAACGRJREFUeNrsnb9rVEsUxyfrQ7AO+AOzAaPGqJhCTKFNSsXCvyBapRDhaZNCbR7pXvE6wcoqRFRiIqQIRlSIRRpBMMEkb/1RKGpUonZqRH3nu+9eifHu3jlzztydDXNgWAi5e89nPndu9s7OnLT8+PHDxAg3SrELoqAYUVAUFCMKihEFRUExtOMPzTd79uzZeno5RK2HWje1Tmplaq3JryxRe0GtQm2G2n1q0x0dHcuhdUwoLC0aD6oE00Uvx6gdpdbLPHyK2gS1cYJbCEBMUCwiQQSzmV5OUOujtk+Yyyy1YWpDBLfYADFBsjgLIqDD9HIqudo0Y5zaRQKbLFBOsCxOggion14GqO3y1Gf/UvuHwC4VICdoFrYgAvqTXv5a8cfSV+CP8CCBXfAoJ3gWlqCnT5/iavu7AKCVYGe3b9+uPpKahaXEADqc3ApEQO/evTPj4+O2v45zDSTn1pTDZkHOyF0QTixWgp48ebKZRtoparsw4lzb27dvzcjICPc4nPMUctCQI2FB7mAQ9AGbxUoQvekJasc05Hz+/Dl9T07DuU9oCHJlQSB3BUksllxBlUqli96wTyrn+vXr5suXLys7itv6kItEjoQlDTCARSjJmqVkccXB+D6JnNHR0V/kOApCDseEo8eZZWWABUwCSdYsdQUtLCyspzc6KpEzNjb2mxxHQWhHkZOLHCnL6gAT2ASSrFjyRtAhh/moaszPz5sbN25kyjlw4IDrIOhNcnIJZ5ZaOYMNjGD1xVLKuSX0uFwdc3Nz5vbt25lyjh8/bnbs2CG5f/c43t56JH9HkTNyz5IEVjD7YMkT1M09Ka6mO3fuZL4fANvb283Hjx8lgrodBXVLBCFn5J4lCQFmsGuz5N3iOpn3eSs5wugs+LifYSMJfaCZU94IKmuNnHK5bD58+CAZOWkrO46gssK5qwxgURpJZekIarUdOXfv3q0rR2HksHJSPC5zJNWThL6wHEmtUkFWMT09nfnznTt3assJJlJJYOT0CTfyBC3ZvMmZM2fMhg0bfvv548ePq88KHmaFizyuZoANjKsDfYE+0cgpT9ALm7N8/frVnD59OlNSvdufY7wo+DjWbQx9gL5An2jklCeoYnMWTCKmklpbW31LqhR8nLUcsKdy0klhaU55gmZsk04lDQwMmLa2Np+SZgo+zkoOmMHOkGOVU56g+5zkkdirV6/MyZMnfUq6X/BxVnLADHaGHKuc8gTho8gU54zfvn0zb9688SVpKsnJ6cMml4UjB8xg12apK2jv3r1YJTnBhcmTlDVHZxkTSU7scGWpl7NAjjWLzXMQFhDMakoqlZwev2aTXCThxJKVs1CONUvJ4srDuB52gcobScwYTnJxDgmLohwWi+2lPOR69SpJGk9y0IghyUhUkMNiKVleeVhffNH8v0qyaEk458UkB3FIWBTksFlYCxcfPXokWuy3bt06s2nTJjM1NVVzDitjKuQsAakvXOSyYEqnt7dXIseJhb30l8BEy2UhCU/c+C7fAmiQgLwt/eWwbNy40SwtLUnkOLE4LZ5Prj7vC859jJxmY3HefkJgXrdsEFBh209CZhFt4CIwL5uetD4QrAUWlS2QBKeybVD6nKMkKiiWFs1iSgTntPHWdfrGs6ggWFpitauwI9ZJiIJiREFRUIwoKEYUFAXFiIKioBhRUIwoaM2EasXFZNcye4Kxq6sruMnSUFhUJksJRmWKnuAWAhATFItIEMF4+ZKL4BYbICZIFmdBBOT1a2ICmyxQTrAsToIIqJCFFgR2qQA5QbOwBRFQoVUKCeyCRznBs7AEzc/PN6RK4e7du9VHUrOwlBhAKhUXFxcXzbVr12x/vVqlMDm3phw2C3JG7oJwYrESNDc3p1Jx8fXr12Z4eNipSiFy0JAjYUHuYJBWXOSwFFZxMZXT7BUXFSTpVlycnZ3t+v79ex8149qwd/Py5cu/7FJzeJ8+5CJ6OBGwpAEGsIBJ0CfWLN4rLuJqu3LlypqruAgmwUjSqbj48OFDUZVCAFy9elW14iJycpEjZVkdYAKbQJIVi7eKizMzM9VPPllyDh486DoIGlZxMStnsIERrL5YvFRcpCvD3Lx5M1NOf3+/oWeBpqu4iJyRe5YksIK5KSou4mqanMyeegJgR0eHef/+fdNVXETOyD1LEgLMYA+64iJ9MrGSI4yGVVy0kYQ+0MxJreJi3sjZtm1bdQths1dcBANYlEZSMRUXcdXcunWrrhyFkcPKSfG4zJFUTxL6wnIkFVNx8d69e9njt7NTW04wkUoCI6dPuKFScfH8+fOZxfwqlUp1asTDrHCRx9UMsIFxdaAv0CcaOalUXFxeXjbnzp3LlIQKuBMTE5r9EkTFRTBlVZxHH6Av0CcaOalUXPz06dNPSVkVF5UlNbziYi05YE/loE80clKruJhKGhwcrFbD9SipoRUXa8kBM9gZcqxyUq24iMSeP39eLQ3pUVLDKi7WkwNmsDPkWOXkpeLiy5cvfUlqWMXFPDlgLrzi4v79+50rLtaTJKm4mOTEDleWejkL5FizeK24WEvSWqi4KJSjV3GRLIsqLtYbSdzHjiQX55CwKMphsRRScVFBUjAVFxXk6FdcJNviiosCSdUqhUkO4pCwKMhhs7AWLj548EBccXHr1q3VL7j27NljOxVyloDUFy5yWfAv0I4cOSKR48TCXvpLYOKKi6heiO/yLYAGCcjb0l8Oy5YtW6pVIiUVF11YnBbPJ1ef9wXnPkZOs7E4bz8hMK9bNgiosO0nIbOINnARmJdNT1ofCNYCi8oWSIJT2TYofc5REhUUi2pBP4Jz2njrOn3jWVQQLLHiYuAR6yREQTGioCgoRhQUIwqKgmKox38CDACL7v6JnTZ+vgAAAABJRU5ErkJggg==)
-
You can also run a search like this to get at these pages: https://encrypted.google.com/search?hl=en&q=site%3Amommyupgrade.com inurl%3A%3F%3Dp
The root cause is a hack of your Wordpress installation, most likely a plugin. Here's a good discussion around how this takes place: https://wordpress.org/support/topic/someone-has-hacked-the-site-and-inserted-a-link
Recently a vulnerability was found in the Yoast plugin (see: http://thehackernews.com/2015/03/wordpress-seo-by-yoast-plugin.html ), so you'll certainly want to upgrade that and preferably set your updates to automatic.
Good luck!
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Building an Industry Resource List w Links to Competitors
Hi folks. I'm working on a B2B e-commerce site in a very commoditized space. It's very technical and longtail-- several thousand product pages and of those, over 1,000 landing pages per month, when visitors find products. Most items we sell are only bought once or twice per year. Many won't even be bought in a given year. So it's tough to invest a lot on a given page, but we chip away at it. We don't have many non-product pages. To date, we've grown with solid on-page SEO for products and good customer service. I'm adding a resource section to include helpful articles and definitions of technical terms. Also, since good sources of products can be so hard to find (we literally have customers like NASA googling for parts), I would like to build an industry guide of sorts. It would include manufacturers, master distributors, distributors and resellers (like our site). To be a good list, it only makes sense to include my competitors. It's likely very few people will actually ever see this page, but I figure more deep content with lots of highly relevant links is good for raising DA, especially because it could become a page others want to link to. I haven't found a comparable resource in the 4 years I've been working on this project. Any reason I should not do this? Any pitfalls I should be aware of? Thank you!
Content Development | | Mike_Sobol0 -
Why is the blog link so often found in the footer?
Hello, Can someone tell me please why are the links to a site's blog not displayed prominently? Why are they hidden away in the footer? Wouldn't making the link to the blog more visible increase traffic?
Content Development | | CyrusDariusXerxes0 -
Need advice on internal links
I run a couple of gadget/technology based blogs, which essentially has news based articles and long form articles such as reviews, tutorials, and tips. Looking for some advice on the strategy for internal links: We have been using internal links in the following ways in articles so far: Links to the category pages at the end of the article (we call it related topics) Links to category pages wherever relevant preferably in the first paragraph. The logic here was that if we can add the link to a category in the first paragraph, which appears on the home page and category page, it will pass the link juice to the category page. Link to relevant articles, mostly by using the full title of the post as we thought that it stands out. Issues with the current strategy: In the case of the 1st strategy, it doesn't seem that natural, so we are not sure if people actually end up clicking them. In case of the 2nd, we have couple of concerns: it could result in linking to a category page twice. One within the article, and the second at the end of the article because of strategy 1. Because the first paragraph also appears on the category pages, it would mean that in some cases we will be linking to the same category page (recursive). In the case of the 3rd strategy, the problem is it does not appear natural so we are sure if it increases the value of the content. I was wondering if we should adopt the following strategy: Get rid of category links at the end of the article. Avoid linking to the category pages in the first paragraph, instead link to the category pages after the first paragraph, so we don't end up with the issue mentioned in b. i. Alternatively, we could remove the excerpts from the category pages so we don't hit the issue of linking to the category page from the category page. Add links more naturally. So have a sentence which talks about the related article and link to it using partial match (keyword phrase) or exact match. Any advice would be greatly appreciated.
Content Development | | Gautam0 -
Are reciprocal internal links weaker than one way?
Hi guys I have an eCommerce site and a blog. the blog is on a suddomain. I am writing content about our products on the blog, I.e. Full in depth reviews and top 10 lists etc. These blog posts link back to the main product page. It would also be nice for customers on the site to a "blogs about this product" section. However, would a link from the product page to the blog weaken the internal link from the blog to the product? Thanks Paul
Content Development | | TheUniqueSEO0 -
How to encourage guest bloggers to link back
Hi, we have just started to allow guest bloggers on our site www.in2town.co.uk where we offer them two links within the articles, but what we would really like to do is to encourage them to link back to their articles. I am trying to find information on how we can encourage guest bloggers to link back and would love to hear your thoughts.
Content Development | | ClaireH-1848860 -
Link juice from subdomain
Does having a blog on a subdomain as opposed to an extension of the root domain add or subtract to improving SEO on the root domain? For eg : what's better, HTTP://blog.durbansouthtoyota.co.za Or HTTP://www.durbansouthtoyota.co.za/blog When the www is the actual main site. Thanks!
Content Development | | ZakD0 -
Deleting a Wordpress Blog Page with no inbound links?
What are the concerns I should have in deleting a WordPress Page that is no longer relevant or a duplicate? Note: This would be a page that does not have any inbound links to it.
Content Development | | CMCD0 -
Blogging competition - risky link acquiring method?
We are planning to launch a competition where bloggers can blog about our products and about our company. One winner will be selected to win a gift card to our web shop. In order to participate the blogger has to put a link to the blog post that points to our front page or into one of our product pages. Does Google have a guideline against such "link acquiring" methods?
Content Development | | EuropeanSEOguy0