Vulnerabilities / Threats
10/17/2012
06:13 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Helps Webmasters Disavow Spammy Links

New Disavow tool gives website owners a way to distance their sites from linkspam.

10 Best Business Tools In Google+
10 Best Business Tools In Google+
(click image for larger view and for slideshow)
Google, to some, is a kind of god. So it's fitting that Google should offer redemption to those who have fallen from favor.

Google has just introduced what it calls its Disavow links tool, a way to disassociate one's website from linkspam.

In Google's book, linkspam is a sin. Linkspam, also known as Web spam or unnatural links, is a term to describe Web links that are deceptive or manipulative. Google sees a lot of linkspam because it treats links as votes for the relevancy of the designated website. Relevant websites appear at the top of search results lists and tend to get a lot of visitors; less relevant websites starve.

Many websites looking to improve their visibility in Google Search find it easier to pay some shady search engine optimization (SEO) firm to create a deluge of low-quality content that links back to the client's site than to craft copy so compelling that Internet users create links unbidden.

[ Congress is coming down hard on Chinese telecom equipment makers. Read What Huawei, ZTE Must Do To Regain Trust. ]

Google tries to discourage paid links, link exchanges, and other schemes designed to influence its relevancy rankings through its webmaster guidelines. But not everyone does the right thing.

Attempting to manipulate Google may pay off for a while, but sooner or later, Google is likely to catch on and the punishment can be severe. Several years ago, BMW was caught gaming Google's search system and Google reduced the PageRank of the offending website to zero, effectively excommunicating it for a time.

In a blog post, Jonathan Simon, webmaster trends analyst at Google, says that the Disavow tool is intended for website owners who have been notified of a manual spam action arising from "unnatural links" pointing at their site.

The first course of action he recommends is removing as many of the spammy links as possible. But because it's not always possible or practical to get in touch with the creators of incoming links, there's the Disavow tool. It tells Google to ignore incoming links that the website owner specifies in an uploaded file.

Google stresses that the Disavow tool is an advanced option that should be used with care. "If used incorrectly, this feature can potentially harm your site's performance in Google's search results," the company says on its website.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.