Someone is using the site to spam subdomains.

iga2024m

Newbie
Joined
Jun 9, 2025
Messages
4
Reaction score
4
The website mayfieldclinic.com is being used for spam on subdomains. Here are some examples, google - site:kink.mayfieldclinic.com



How is this done? How can it be prevented?
 

Attachments

  • Screenshot 2025-06-09 043249.jpg
    Screenshot 2025-06-09 043249.jpg
    137 KB · Views: 70
The website could be hacked,.Can't say here ,this forum is not a hacking forum and its against the rules
 
If they are creating new subdomains then likely either their DNS provider or cloudflare has been hacked.
 
An interesting fact is that this is not the first domain he has created subdomains for. I noticed that all of the domains have the following NS servers

ns77.worldnic.com

ns78.worldnic.com



There may be a vulnerability on this hosting service that allows subdomains to be created. The website https://mayfieldclinic.com/ has https, but the subdomains for spam are created on http.
 
So, is the subdomain actually getting the authority from the main domain? Or how does that work? I thought subdomains are considered a different domain and dont inherent the authority from the main domain?
 
This is called subdomain takeover and is extremely common unlike what most people think. Considering that creating a subdomain such as kink is less probable, the site might be hacked.
 
So much nonsense.

The question is if the subdomain is actually getting "juice" from the main domain or is treated as completely new domain.
That was NEVER the question. The questions were:

  1. How is this done?
  2. How can it be prevented?
Those questions have been answered in the resources I shared in here. That was THE SENSE, the SOUL of this post.

You should know that Google treats subdomains as separate entities from the main domain. This means a subdomain's search rankings, authority, and "juice" are not directly inherited from the root domain. John Mueller, a Search Advocate at Google: "Google doesn't treat subdomains differently than subdirectories for crawling or indexing purposes. However, the systems that determine ranking do. They treat them as separate sites."

If you need more elementary information about this, check out this video, it may help you to understand this better:
 
That was NEVER the question. The questions were:

  1. How is this done?

I know how it is "done" and it has nothing to do with what you wrote about "symlink race".


You should know that Google treats subdomains as separate entities from the main domain. This means a subdomain's search rankings, authority, and "juice" are not directly inherited from the root domain. John Mueller, a Search Advocate at Google: "Google doesn't treat subdomains differently than subdirectories for crawling or indexing purposes. However, the systems that determine ranking do. They treat them as separate sites."

If that is the case, why would anyone use these subdomains? And then get them all indexed?

The video you posted is from - buckle up - 12 years ago. So, I have doubts. Seems like one of the myths posted and then continuously repeated over and over.
 
I know how it is "done" and it has nothing to do with what you wrote about "symlink race".




If that is the case, why would anyone use these subdomains? And then get them all indexed?

The video you posted is from - buckle up - 12 years ago. So, I have doubts. Seems like one of the myths posted and then continuously repeated over and over.
I have done this before using Symlink race, and I know for a fact that Network Solutions is vulnerable to such.

Answering your question:
If that is the case, why would anyone use these subdomains? And then get them all indexed?

While the video I referenced was older, its core message remains relevant. Google does indeed treat a subdomain as a separate site.

The attacker's goal is to leverage the main domain's authority. While Google treats subdomains as separate sites, a strong root domain can sometimes help new subdomains get indexed quickly. The attacker is essentially "parasitizing" the trust and authority of the compromised main domain to get their spam content into Google's index.

By creating thousands of subdomains, the attacker is essentially playing a numbers game. They publish spam content across a huge number of subdomains, hoping a percentage of it will get indexed and rank for various search queries.

The goal is to drive traffic to these spam pages, often for affiliate marketing, phishing, or other malicious purposes.

Therefore, the symlink race attack was the method used to compromise the server, and the creation of spam subdomains was the result of that compromise an SEO-based attack designed to get thousands of junk pages indexed by Google.
 
While the video I referenced was older, its core message remains relevant. Google does indeed treat a subdomain as a separate site.

contradicting ->

The attacker's goal is to leverage the main domain's authority. While Google treats subdomains as separate sites, a strong root domain can sometimes help new subdomains get indexed quickly.

So, yeah, exactly. It's inconclusive if subdomains aren't getting the authority from the root domain.

Also, since you are contradicting yourself... I checked your messages:

Capture.PNG

Therefore, the symlink race attack was the method used to compromise the server

Bro, stop that. It's not "symlink race" or whatever buzz word you want use.
 
contradicting ->



So, yeah, exactly. It's inconclusive if subdomains aren't getting the authority from the root domain.

Also, since you are contradicting yourself... I checked your messages:

View attachment 464980



Bro, stop that. It's not "symlink race" or whatever buzz word you want use.
1.- You don't know what Symlink race is. That let me know you haven't checked the resources shared in here or you didn't understand that. This is not a "buzz word.


2.- I don't see the contradiction. The attacker is using the root domain authority to index the spammy subdomains. That's it. The "authority juice" is just to INDEX them.

3.- To give you a clear example:
When you make a new account at wordpress.com, you get a subdomain like youraccount.wordpress.com. The benefit or SEO juice you get from wordpress.com to your account? None. It will help you to index the new link in Google, but your domain authority will be 0.
 
So the root domain gives power to the subdomain.
The root domain will tell G to index the entry of the subdomain. But that's nothing related to "power".

How do I know this is a symlink race attack? If you saw the screenshot shared by @iga2024m and me, you'd see the exact same date on the files uploaded to kink.mayfieldclinic. That date format is a distinct indicator of an uploaded file, not a newly created one.

This is visible if you search for the same "print" in other compromised websites.

1754730024525.png
 
The root domain will tell G to index the entry of the subdomain. But that's nothing related to "power".
How would Google even know that the subdomain exists if it's not "indicated" somewhere. What does that have to do with the root domain?



How do I know this is a symlink race attack? If you saw the screenshot shared by @iga2024m and me, you'd see the exact same date on the files uploaded to kink.mayfieldclinic. That date format is a distinct indicator of an uploaded file, not a newly created one.

This is visible if you search for the same "print" in other compromised websites.

View attachment 464984

I don't know how this date besides the url in Google search results shows up, but there can be absolutely no conclusion be made that this is because of "uploading". And hacking a domain can be made by a number of ways and "symlink races" is just a nonsense buzz word. More likely it's just a Wordpress vulnerability or xss or sqli gaining access to a panel (like cPanel).
 
How would Google even know that the subdomain exists if it's not "indicated" somewhere. What does that have to do with the root domain?





I don't know how this date besides the url in Google search results shows up, but there can be absolutely no conclusion be made that this is because of "uploading". And hacking a domain can be made by a number of ways and "symlink races" is just a nonsense buzz word. More likely it's just a Wordpress vulnerability or xss or sqli gaining access to a panel (like cPan

How would Google even know that the subdomain exists if it's not "indicated" somewhere. What does that have to do with the root domain?





I don't know how this date besides the url in Google search results shows up, but there can be absolutely no conclusion be made that this is because of "uploading". And hacking a domain can be made by a number of ways and "symlink races" is just a nonsense buzz word. More likely it's just a Wordpress vulnerability or xss or sqli gaining access to a panel (like cPanel).
1754775108280.png
 
Back
Top