Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Monday, 22 September 2008

Manipulate the BBC's most emailed stories

The BBC's 'most emailed' stories is based on very small numbers. So small in fact that by emailing yourself a few times you can manipulate the results, apparently...

BBC's most emailed stories widgetI read about this in the latest issue of New Scientist (scroll half way down the page to “Rigging the ranking”).

Chris McManus in the above article managed to get an old story to appear at number 4 by emailing himself 5 times. I've just tried this (albeit at 10am, which may be a relatively busy time) and emailed a random story to 12 different people and it hasn't appeared.

I would say this sort of manipulation is clearly on the wrong side of the SEO law so i'm not going to recommend it but it's interesting nevertheless to see that a site as large as the BBC still only has very small figures to make up it's most emailed stories, if McManus' story is indeed true.

Looking at this on Wikipedia provides a link to a PDF article from the International Journal of Computer Science and Network Security called Statistics Hacking - Exploiting Vulnerabilities in News Websites (by Amrinder Arora) which identified BBC vulnerabilities back in March 2007. There must be spammers out there capable of manipulating this on a large scale, hiding their proxy, using multiple emails e.t.c.

I can't imagine the BBC are oblivious to this even though they have left it for over a year so i'll let you know if they come knocking on my door.

Related posts
BBC increase most read stories to top 10
Online popularity culture is killing good journalism - writing content for the benefit of most read and most emailed widgets
Feedjit widget provides your site's most popular pages

Monday, 14 July 2008

Spammers target web nerds with Homer's email address

Now most spamming, even clever spamming, tends to reek of spam to even fairly innocent web users. But this recent scam reported on the Register (full details of the scam) about using a screenname from a Simpsons' episode, that was originally in use by none other than writer/producer Matt Selman, was particularly crafty.

I'm actually quite impressed with the ingenuity of these spammers but they've fallen at the last hurdle by picking on someone their own size!
  1. They've thought of a really clever way of contacting people where the person is likely to trust them and they can send them a personal message without it being picked up by a spam filter.
  2. Then they've sent them a message advertising a 'web only' Simpson's episode that links to spam.
  3. What they forgot was that the only people who watched this episode and then added chunkylover53 to their buddy list were nerds!
Don't target the most streetwise web users around. Nerds talk to each other on forums, they check before they click, and then they post blog articles (and another) about it to warn others.

You need to be targeting the elderly and the young, not walking up to 15 rugby players and asking for a fight.

I've always wondered why such technically adept spammers don't earn big money working for IT firms, now i know why. D'oh!

Related posts
7 top tips to avoid email spam, phishing and fraud

Thursday, 12 June 2008

Do rel=nofollow tags on internal links benefit your site's SEO?

Well yes, using rel=nofollows on your internal link structure is an advanced SEO technique but it can help to improve your SEO. [See update at end of page, it's likely this technique no longer works].

I asked this question on LinkedIn a couple of weeks ago and what follows is a summary of some of the responses I received and other research I’ve done online.

What is it?

“A site may have many pages that have the opportunity to get crawled and indexed in the SERPs (search engine results pages). You're also looking at near infinite choices for how you interlink all those pages. Out of all those permutations, there is one configuration that is the most optimal from an SEO perspective.

That's because it maximizes the flow of link juice (e.g., PageRank if you're speaking purely in Google terms) to your most important pages and minimizes (or cuts off completely) the flow of link juice to your least important pages.” - Stephan Spencer at Search Engine Land

By adding rel=nofollow to a link you are telling a spider not to follow that link. This was invented to be used in comment fields to prevent comment spam. However as all it does is prevent link juice being passed on, SEO specialists have realised it can be used (completely legally, Google even approves it!) to sculpt internal linking structures.

Example: If you have 100 internal links on a page you are diluting that page’s link juice. By adding rel=nofollow to 90 of the less important links the 10 that remain have 10 times more link juice and subsequently benefit the pages they link to more.

Site structure
Before I get onto the use of rel=nofollow it’s worth considering that this technique is used to fine tune internal linking structure. There’s no point in fine tuning your internal linking structure if it’s sculpted incorrectly in the first place.

“The size and shape of your site's navigational hierarchy is your blunt instrument and rel=nofollow is your scalpel.” - Stephan Spencer at Search Engine Land

“One of the most powerful, and most underdeveloped, on-page SEO tactics is rejigging your internal hierarchical linking structure to optimise the flow of link juice.” This makes sense from an SEO point of view but also from a user point of view – if all your information is arranged in a logical structure it will make for a better user experience.

Using rel=nofollow
So if your site structure is as perfect as you want it, you’ve tried card sorting, user testing and the hippo (Highest Paid Person’s Opinion) is happy then it might be time to look at using rel=nofollow.

First check you have a good xml and HTML sitemap on your site. As Tom Griffin stated in the LinkedIn answer, “The goal is not to block the page from being indexed - the goal is to funnel internal authority throughout your site in the smartest way possible”.

Then you need to select which pages on your site you identify as the most important (and least important) for the relevant keywords you target. This in itself is a worthwhile task for any webmaster. There could be many pages on your site which rank highly for certain keywords but are underused due to being buried in your site structure. The links from those pages could be a massive boost to other pages on your site.

Next is the big one - look at the pages themselves and identify all the links. Clearly this could be a mammoth task even for a site of a few 100 pages so start with the biggie – the home page.

I haven’t tried this yet but I’d recommend creating or using some sort of database or record of which links are on or off (rel=nofollow) to best understand the impact you are having on your site structure. As mentioned above you don’t want to risk creating a dead end and cutting off a page.

Real life examples
SEOmoz have implemented rel=nofollow on their site and witnessed a 20% rise in traffic. However others are more sceptical; Matt Cutts from Google says that nofollowing your internals is a 2nd order effect. It will best optimise the traffic you have rather than gain you more. Essentially he believes there are others things you can do first for a better return on investment.

Conclusion
And my final question on LinkedIn was why aren’t the big sites doing it?

Bbc.co.uk, theregister.co.uk, look in their source code and you won’t find one rel=nofollow tag. The only answer I can think of (and the only answer I got on LinkedIn from Brian Rogers) is that if you have a perfect link structure and your pages rank very highly due to large amounts of external links what difference will fine tuning your internal links make? Or maybe it’s just too complicated?

So to summarise, it’s worth it and it works. How worth it is something only you can decide and, to bore you with clichés, this is only one tool in the SEO armoury.

Update, June 09: Apparently Google now ignores pagerank sculpting such as this. More on Google's Matt Cutts' blog.

Tuesday, 18 March 2008

Cybersquatters can redirect your users to porn

By ever so slightly misspelling a url or adding an incorrect .com when it should be .org there's a very high chance you'll end up looking at porn.

It's happened to me twice in the last two days.

First of all i was attempting to direct an IT colleague to www.videolan.org in order to download VLC media player and inadvertantly directed him to www.videoland.org, something very different.

Secondly i was meaning to type in the domain www.veganza.org to view the Church of the Flying Spaghetti Monster however i forgot the .org and typed in www.veganza.com and was yet again viewing naked ladies.

Now 'accidentally' looking at porn isn't the most painful experience you can have but with a computer screen that everyone in my open plan office can see, being caught viewing animated gifs and rotating flash graphics of unhygienic sex acts isn't a desired career move.

The only way to avoid this surreptitious adult surfing is obviously by being a bit more careful and possibly finding a website through Google so you can get a text preview before the onslaught of technicolour karma sutra.

Telling you how to not view porn isn't the point of this article though, what my recent experiences highlight is the importance of your url and how it's important to be aware of 'cybersquatters'.

"Cybersquatting, is registering, trafficking in, or using a domain name with bad faith intent to profit from the goodwill of a trademark belonging to someone else. The cybersquatter then offers to sell the domain to the person or company who owns a trademark contained within the name at an inflated price."

There has been a number of high profile cases of this happening, notably to Harrods in 2001; they won the case and got the domains. Harrods is a big brand name and was seen as an easy target for cybersquatters of the early noughties but as the two examples at the beginning of this article show, anyone can be a victim of cybersquatting.

With 108,810,358 distinct websites and still counting even picking a domain name without standing on someone else's toes becomes tricky.

  • So when picking a new domain name try and be original and have a look around. Are there sites with similar URLs that could confuse your users? If they are cybersquatters you may be able to evict them but if they have a genuine claim to that URL there's little you can do (bar pay for it like the BBC did).
  • If you already have a domain name then have a check for cybersquatters on similar URLs
  • If you're doing any link building make sure that when somebody links to your site they get the right domain name
By doing this you can hopefully make sure your users only look at porn when they want to.

Saturday, 8 December 2007

7 top tips to avoid email spam, phishing and fraud

As the web gets more sophisticated so does phishing (fraudsters trying to gain your personal information through masquerading as a trusted source).

One of my colleagues recently received the below spam/phishing email:
Date: Thu, 6 Dec 2007 19:18:58 +0800
From: Mars.zhou@netinchina.org.cn
To:
Subject: Domain names of Shedshow (to CEO)

Dear CEO,

We are the domain name registration organization in China, which mainly deal with international company's in china. We have something important need to confirm with your company.

On the Dec5, 2007, we received an application formally. One company named "Jufeng Holdings Limited" wanted to register following

Domain names:

shedshow.cn
shedshow.com.cn
shedshow.com.hk
shedshow.com.tw
shedshow.hk
shedshow.mobi
shedshow.net
shedshow.net.cn
shedshow.org.cn
shedshow.tw

Internet brand keyword:

shedshow

through our body.

After our initial examination, we found that the keywords and domain names applied for registration are as same as your company's name and trademark. These days we are dealing with it. If you do not know this company, we doubt that they have other aims to buy these domain names. Now we have not finished the registration of Jufeng company yet, in order to deal with this issue better, Please contact us by telephone or email as soon as possible.

Best Regards,

Mars zhou

China Net Technology Limited
Tel:+(852)-3059-3057
Fax:+(852)-3059-3080
Email: Mars.zhou@netinchina.org.cn

Web: http://www.netinchina.org.cn
A quick web search on some of the sentences within this email revealed other people who'd received this and replied, in many cases with quite shocking results (read the article comments). This forum also linked to in the above article features more people who've encountered this particular scam.

But what if you don't realise it's spam? In fact before this email was brought to my attention one of my colleagues had replied (any further emails i receive from these scammers i will be ignoring and deleting).

It's very easy to get duped. So, 7 top tips to avoid being scammed:
  1. Do you know the company / person emailing you?
    • If you answer 'no' to this question then this is where you should question the email's credibility.
  2. Do some research - the first hit i found on Google for "China Net Technology Limited scam" was somebody who'd received the same email.
  3. Does the email ask you to take action / spend money? - if 'yes', beware
  4. Can all the information they've included in the email be gained without knowing you? - if 'yes', beware
  5. Speak to people you know - if the email talks about domain names then contact your domain provider. If they ask for bank details contact your bank (using the number you know, not the number that may be in the scam email). If they ask to confirm your Paypal details contact Paypal (again not from links in the spam email but via the Paypal website).
  6. Beware lookalikes - It's very easy to make something look genuine online, for example a scammer could buy lloydstsb.org (as opposed to the real lloydstsb.com) to pretend to be your bank.
  7. Calm down - it may seem obvious but a genuine bank request or a genuine domain enquiry won't ask for immediate response and won't do so buy email, more likely than not they'll go through more official channels and post a letter to your home address or alert you when you log in to your ebanking or domain account (again using the URL you know NOT one in an email).
Related posts
Spammers target web nerds with Homer's email address