This Guy Literally DOMINATES the first 5 PAGES of Google!!

An old trick - many ( look up site:mossnest.com.au weight loss ) interlinked doorway pages on hacked trusted sites, couple of backlinks to these pages, a redirection - et voila. A few years ago pharma tops were all dominated by the similar doorways on .edu domains.
 
This guys doing some pretty simple yet sophisticated stuff. It just further shows that Google doesn't have a clue about what they are doing when stuff like this gets by without any issue.

Nearly all of the titles are the exact same on every SERP with manufactrured ratings and "updated" content dates.

It's using a simple referrer redirect for visitors that visit from the SERPs. It looks like these are hacked websites in which the Webmasters don't know what's happening on their domain. Taking a look at most of the homepages they all seem to be live and active websites. My guess is some simple unpatched exploit to have a network of sites for this purpose.

Then each website links to another site that is controlled by this guy, essentially linking quality domains among eachother so that they all rank well.

Go Google!
I'm pretty sure that the guy owns all of the sites. Look at the cached versions, many of these are styled identically, with the same low quality spammy content.

http://webcache.googleusercontent.c...nts-ephedra-290.htm+&cd=2&hl=en&ct=clnk&gl=us




http://webcache.googleusercontent.c...nts-ephedra-404.htm+&cd=3&hl=en&ct=clnk&gl=us
 
In MOST countries, there are many laws about accessing sites without permission, its called hacking and you go to prison for it.

What's worse, in the US, they often ban you from owning a computer or accessing the web forever as the terms of your release.

The rest of your life with no Internet, not for me.
 
That only means that he uploaded sites with same design not that he owns the domains where the sites are uploaded.

That shit is intense. How do you protect yourself from something like this with your own domains? I'm not very "well-read" on this subject, or web security in general...just speculating.
 
What you've found is the tip of the iceburg. Google ....

Code:
intext:"rapid weight loss now"

Also, I wouldn't even think about hacking. In the US and UK you'll go to prison if caught, especially if it involves making money. I've been to prison for hacking. Don't get involved in it, it's a waste of life if you're caught.
 
Last edited:
Some of his sites are already being banned. I see quite a few of his domains disappearing.

Snitching on competition is really low. I'm sure those who are outing sites and keywords here know that karma bites back HARD.

If you really care about 'his' sites, you shouldn't bump this. The thread was buried in page 4 but you kicked it to the top. You know G webspam team visit this forum often, right ?
 
Last edited:
That shit is intense. How do you protect yourself from something like this with your own domains? I'm not very "well-read" on this subject, or web security in general...just speculating.

For one don't install unnecessary plugins. This is probably the worst thing people do - they install plugins for everything and typically they can get rid of 90% of them.

Keep your shit up to date, that's another big one. Not only Wordpress but plugins as well.

Don't use Admin as a username, use a password generator and a strong password. Make sure you have some kind of security that will lock people out if they attempt to brute force. Don't broadcast your WP version in your source code.

I'm no security expert but start with those basic tips.
 
That shit is intense. How do you protect yourself from something like this with your own domains? I'm not very "well-read" on this subject, or web security in general...just speculating.
Simple solution is => Don't use wordpress or similar readymade products.

Everyone check out your wordpress sites. View source code and go to bottom of it and see if there is any unknown code.
 
That shit is intense. How do you protect yourself from something like this with your own domains? I'm not very "well-read" on this subject, or web security in general...just speculating.

Most compromised sites are either exploited because they are running old server versions, hacked plugins,not updated scripts etc..or the site owners are keylogged and probably installed malware. Anyway you can never be truly 100% safe even if you secure the domains and your sites from being exploited there is still a possibility that you can install some sort of malware and expose your site logins, server passwords etc..
 
Last edited:
How to get this kind of fake "reviews"?
With any Plugin?
 
Theme Authenticity Checker is a good one to use for links added to your sites.Also b4 you upload, always check for obfuscated code -- if you find some decode it b4 you upload it. Change the database name -- by default your database has a default prefix of wp, change it -- even if you add a random char to it your much more secure. Never use admin, administrator or ANY variant on them. Always use privacy on domains that are important -- a lot of hacks involve calling your hosting company and try to get some one there to give you the login information with a sob story.
If you look at source as suggested, use find and search for http, www etc. As suggested above, do NOT broadcast your wp version number in the code.
Also check your computer daily! I see people who get reinfected from their own computer.
Use these and the great ideas suggested above for a great start. There are lots more that can be done, but these items gets rid of a lot of attackers. The goal is to make them decide, why waste time here, when there is another site thats easier and does what I want!
 
This guy is a fool... If he would send the traffic tto a squeeze page instead of direct linking he would make infenitly more!
 
That's definitely the way to do it. Shows how good google are at fighting spam as well :-)
 
This guy is a fool... If he would send the traffic tto a squeeze page instead of direct linking he would make infenitly more!

We can leave that to a split test. Since this will require a "full converting" user to enter emails 2 times and get frustrated instead.
 
Back
Top