19 August 2008

SQL Injection Poses Search Engine Optimisation Threat

Web sites that have been compromised by the recent wave of SQL injection attacks on ASP and PHP based sites have plenty to deal with already, but it seems a threat to their search engine ranking may be a longer lasting problem.

SQL injection is an attack where nasty input (you might hear this referred to as "maliciously crafted parameters or names") is sent to web applications - typically in page addresses or form submissions. If the application doesn't validate the data correctly, it can be used to compromise information in an associated database. This may cause loss, destruction or alteration of data. Recent attacks have added malicious code into page content with the aim of compromising people visiting the hacked sites, if the page output is not validated and encoded correctly.

You can find compromised web sites by searching for the JavaScript code embedded in the content after it has been re-indexed by search engine crawlers (robots). However, it looks like some of these are being removed from search engine catalogues, meaning the site will suffer from a significant reduction in traffic from people using search engines (natural searches).

Site owners should of course ensure their sites are not liable to SQL injection attacks, but I think they should also monitor changes in search engine rankings and visitor traffic patterns.

Has anyone had this affect them?

Posted on: 19 August 2008 at 09:16 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
SQL Injection Poses Search Engine Optimisation Threat
http://www.clerkendweller.com/2008/8/19/SQL-Injection-Poses-Search-Engine-Optimisation-Threat
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2008/8/19/SQL-Injection-Poses-Search-Engine-Optimisation-Threat
Requested by 38.107.191.109 on Wednesday, 8 September 2010 at 00:40 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2008-2010 clerkendweller.com