Webalizer Black Hat SEO Stunt
May 19, 2009
While surfing around on the net randomly I made a few discoveries and if you know a little about SEO you will see that it is at the same time genial and disgusting. I’m going to show you how the black hat seo-kids get a large number of very valueable links from sites we all (including Google) really trust. The example I’m going to show you is my old Uni at UU.se.
First of all I want to tell you how I came upon this knowledge. I was looking at one of the first sites I built and realized that the Webalizer stat pages could actually be viewed by anyone. If a site has Webalizer (or I learned Awstats) there is a big chance that you can just add /webalizer/ and take a peek at their visitor statistics. This is of course a big flaw in it self but there is an even bigger flaw hidden in this information. Some versions of Webalizer (2.01 I learned is the one being targeted) present referrers as links, proper good old fashion, search engine friendly, links.
This means that if you refer people to the site and make sure their Webalizer stat page is indexed, you will get a link. Combining this with referrer spam, just sending visits by proxy claiming to come from your site will get you on the Top 30 referrers in no time. I started wondering if anyone had actually found this bug before so I started doing some Googling and did actually find a lot of sites with indexed Webalizer pages. The key phrase here is the strict “Generated by Webalizer Version 2.01″, try it and you will find a lot of them. At the time I didn’t realize this was the term to use so I tried a number of them until I actually ran in to my old University. They happened to have this page indexed. I have pointed out this flaw to the Uni so they might fix it but I got a screenshot of what you can find under Top Referrers.
I later learned that most of this referrer spam is created by using a tool called PRstorm, which does exactly this. Now to the important part, I would suggest you don’t try this, it’s both rude and risky. Getting inbound links like this makes the risk of getting excluded from Googles index very high and you are being a nasty guy by spamming the sites.
This article was translated from my Swedish Blog.