Over the weekend, Monetize, a blog dedicated to tricking search engines, described how a blackhat got Google to index over 5 billion webpages within three weeks. Yahoo and MSN were fooled, too, though nowhere near as badly. (MSN, for example, indexed just 62 pages before cutting him off.)
Searchers who landed on the pages were treated to copy scraped from legitimate websites, along with Pay-Per-Click ads from Google or Yahoo.
The effort seems to have met some success. Third-party traffic monitor Alexa noticed enough activity to rank at least one of the rogue sites among the 2,000 highest traffic sites on the web. That’s a phenomenal ranking for any site, especially a three week old site based in Romania.
According to Ana’s Lair, the search spoofing project was really fairly simple. In the end, the scheme required an SQL-driven auto-page generator, a modification of DNS software, and redirection/cloaking code to show Google one thing and the user something else.
Importantly, the bogus pages also enjoyed links from websites with a reasonable Google Page Rank (like “5″). This in turn, elevated the pages in search engine results.
As the blackhat considered all other avenues deliberately, I’m guessing that an automatic PPC ad clicker was part of the scheme, too.
Suddenly it all makes sense.
Over the last several months, all the searchers in our shop have complained about search results that were becoming increasingly clobbered up with useless citations, like http://2333.water.eiqz2q.org.
At the same time, we’ve watched Pay-Per-Click activity and costs climb, while actionable responses were plummeting. Our solution has been to start rehashing old advertising decisions. Others are suing.
Back in April, spyware hunter Ben Edelman charged that some adware automatically clicks on pay-per-click advertisements presented by Yahoo on the websites of Yahoo syndication partners. And Edelman named names.
He has since joined the legal teams are pursuing Yahoo for enabling Pay-Per-Click fraud.
In addition, Google recently settled a class-action lawsuit for $90 million.
As searchers and advertisers grow more restive, the Search-and-PPC biz looks increasingly dicey… especially for those who depend on it for over 90% of their revenue, like Google, whose SEC filing reminds:
The Company’s revenues are principally derived from online advertising, the market for which is highly competitive and rapidly changing. Significant changes in this industry or changes in customer buying behavior could adversely affect the Company’s operating results.
Among the 22 changes that might cause damage, Google lists 10 worries directly related to search and PPC:
- Our ability to continue to attract users to our web sites.
- The level of use of the Internet to find information.
- Our ability to attract advertisers to our AdWords program.
- Our ability to attract web sites to our AdSense program.
- The mix in our net revenues between those generated on our web sites and those generated through our Google Network.
- General economic conditions and those economic conditions specific to the Internet and Internet advertising.
- Foreign, federal, state or local government regulation that could impede our ability to post ads for various industries.
- New technologies or services that block the ads we deliver and user adoption of these technologies.
- The costs and results of litigation that we face.
- Our ability to manage click-through fraud and other activities that violate our terms of services.
What the world needs now is someone with global reach, clean search results, and thoroughly authenticated ad servers.
Could be just what the doctor ordered… for Microsoft?

7 comments
Comments feed for this article
June 20th, 2006 at 12:05 pm
Jason Kolb
I agree, and I actually think that this is a function of Google’s popularity. I actually posted on this a few weeks ago at http://jasonkolb.typepad.com/weblog/2006/05/google_is_dying.html
June 20th, 2006 at 12:47 pm
Mario
In spite of Google’s well-known pontificating implicit in its “Do No Evil” slogan/motto/creed, they sidled up to the Chinese government tyrants to make a buck. After a public outcry and bad press the top googler eventually conceded that maybe that wasn’t the right thing to do. And now they rake in their cut from billions of bogus web pages. They either need to change or they need to change their slogan/motto/creed.
June 20th, 2006 at 9:20 pm
George
Not only do they gladly accept spam sites in their index, but they also allow scraper sites with stolen content. I have several sites that has been scraped of content and Google even display these sites above mine which is rediculous. Some sites has also disappeared from Googles index for no reason, at least nothing I know and understand and they are not kep accountable since they don’t even answer anybody emailing them. All you get is acanned email saying “Yeah, yeah… we’ll notice it…”
george @ http://www.locateprisoner.com
June 21st, 2006 at 12:25 am
JCV
I run a website using adsense, and I personally feel that there is not enough disclosure on Google’s part as to how much clickfraud actually takes place, let alone how much money each click is really worth. Additionally, I run adwords advertising, and the price per click on keywords is just silly. The keyword minimums just go up and up without any idea of what people are paying for the ads. I don’t like it but it makes me money, so I can’t complain. As an investor I would never buy a share of google’s stock. They are not transparent enough for me.
-JCV
http://www.marketlinks.org
June 21st, 2006 at 2:23 pm
BJ
As a pre-monetization Google fan, I find GOOG’s lightning-speed descent is a painful thing to witness… and don’t get me started on the Chinese collaboration.
fyi: Jason Kolb’s post of 23 May (which he refs in his comment above) is a worthwhile read.
June 22nd, 2006 at 1:12 pm
Ks
you helped expose one kind of fraud, but what about all those sites that do the same thing with a reg URL - we have a site jetaway hawaii - do a search for that term and you will find 1 in 3 results is a scraper of our google ads.. because of you it seems google took action against your finding but are they going to do anything about these other kinds? any idea? I know they cost us money and visitors as well as ranking on competitive words - thanks for your work on this though .. i see my spam results are much less than they were before it was 1 in 2 with the spammy site ranking higher than the legit one.. (BTW JAH follows all google guidelines and is w3c compliant)
June 22nd, 2006 at 2:54 pm
BJ
Hi Ks.
We’re working on a couple of PPC-fraud stories.
If you can provide detailed specifics, email them along with contact info to emailbattles@nospammail.net.
Remember, I said “specifics” not rants. Leave the rants to the professionals.