Vulnerabilities / Threats
10/17/2012
06:13 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Helps Webmasters Disavow Spammy Links

New Disavow tool gives website owners a way to distance their sites from linkspam.

10 Best Business Tools In Google+
10 Best Business Tools In Google+
(click image for larger view and for slideshow)
Google, to some, is a kind of god. So it's fitting that Google should offer redemption to those who have fallen from favor.

Google has just introduced what it calls its Disavow links tool, a way to disassociate one's website from linkspam.

In Google's book, linkspam is a sin. Linkspam, also known as Web spam or unnatural links, is a term to describe Web links that are deceptive or manipulative. Google sees a lot of linkspam because it treats links as votes for the relevancy of the designated website. Relevant websites appear at the top of search results lists and tend to get a lot of visitors; less relevant websites starve.

Many websites looking to improve their visibility in Google Search find it easier to pay some shady search engine optimization (SEO) firm to create a deluge of low-quality content that links back to the client's site than to craft copy so compelling that Internet users create links unbidden.

[ Congress is coming down hard on Chinese telecom equipment makers. Read What Huawei, ZTE Must Do To Regain Trust. ]

Google tries to discourage paid links, link exchanges, and other schemes designed to influence its relevancy rankings through its webmaster guidelines. But not everyone does the right thing.

Attempting to manipulate Google may pay off for a while, but sooner or later, Google is likely to catch on and the punishment can be severe. Several years ago, BMW was caught gaming Google's search system and Google reduced the PageRank of the offending website to zero, effectively excommunicating it for a time.

In a blog post, Jonathan Simon, webmaster trends analyst at Google, says that the Disavow tool is intended for website owners who have been notified of a manual spam action arising from "unnatural links" pointing at their site.

The first course of action he recommends is removing as many of the spammy links as possible. But because it's not always possible or practical to get in touch with the creators of incoming links, there's the Disavow tool. It tells Google to ignore incoming links that the website owner specifies in an uploaded file.

Google stresses that the Disavow tool is an advanced option that should be used with care. "If used incorrectly, this feature can potentially harm your site's performance in Google's search results," the company says on its website.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8148
Published: 2015-01-26
The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.

CVE-2014-8157
Published: 2015-01-26
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVE-2014-8158
Published: 2015-01-26
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVE-2014-9571
Published: 2015-01-26
Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter.

CVE-2014-9572
Published: 2015-01-26
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.