
Want a link?
1. Download the blank,
2. Write in your own clever comment
3. Post it on your blog.
Then let me know about it (comment, trackback, contact form).
I’ll link up all the best ones later this week.

Want a link?
1. Download the blank,
2. Write in your own clever comment
3. Post it on your blog.
Then let me know about it (comment, trackback, contact form).
I’ll link up all the best ones later this week.
Destone has released the code for a referral spammer to the public.
Referral spamming is the action of sending multiple requests to a web site with a “referral url” that you want to promote (like your latest viagra spam site for example). Then, you want either a webmaster to be curious about who is sending them traffic and visit the site by inspeting the logs, or (more often) you want the websites referral logs to be published (thereby creating free backlinks).
About 4 weeks ago, one of the posts on the private SEO Black Hat Forum showed how to get your content indexed on a Google Domain AND have backlinks that counted from the big G.
Here was the original post:
I call this the Google PDA Hack as that is simply what it is. A small breach in Googlebot makes it index it’s own PDA search results.
This will probably not last for a whole lot longer as more and more people are starting to use it but anyhow here is a quick guide on how to.
1. Let’s first see it in action
http://www.google.com/search?hl=en&q=round+and+brown&
btnG=Google+SearchSecond listing
http://www.google.com/pda%3F&as_q%3DRound+N+Brown+site:
kimosabi.en.wanad oo.es&num%3D202. To get your site listed with the PDA hack its important that the site you want listed is already indexed by Googlebot otherwise it wont show and even more important it is that your domain don’t get banned. F.x last week some guy refspammed the [heck] out of this gimmick and he was 3rd on Viagra so his domain was listed under the PDA search pages but no pages was indexed as he was banned. Don’t make that mistake. Just get your pages indexed don’t get them ranking. The PDA hack will do that for you.
3. Now we change the pda search string. It’s easy as ABC.
http://www.google.com/pda%3F&as_q%3DSearch+Term
+site:domain.com&num%3D204. Ok now you ready with your PDA search string. Simply take it and get it linked from somewhere and you should be in the SERPs in no time.
That’s all folks!
It’s funny, because a couple of people PM me saying they can’t find anything to use in the forum – while others tell me it’s far and away the best forum they’ve seen.
Most of us knew the Google PDA Hack was incredible; we also knew it would not be around forever. Alas! The exploit has been fixed — but it was great while it lasted! Several people IMed me about how they were raking in the cash on very competitive SERPs because of this Google PDA hack.
Indeed, Black Hat SEO is a constantly evolving art form. That’s why if you have the tools and knowledge to take advantage of an exploit when it becomes available, you want to be one of the first to know about it.
Is this kind of information worth paying money for? Well, not for everyone. Clearly my Grandmother would not have benefited from having this information 4 weeks ago. On the other hand, many of our members were able to abuse this exploit before it was patched up and made more than enough to pay for YEARS of membership to the Private SEO Black Hat Forum.
Will joining the forum be worthwhile for you? Maybe. Maybe not. It’s definiately not for everyone. However, your opportunity to “peek under the hood” for $100 will soon be coming to a close . . .
You know that the best SEO Black Hats are doing something more than scraping, using a site generator, comment spamming, and pinging to be raking in more than $100k per month.
But what is it?
Right now, there is way too much good stuff that I simply can’t publish on the SEO Black Hat blog. If I posted these tactics and exploits they would immediately get all the wrong kind of attention. The detailed conversations about how exactly to abuse search engine algorithms, generate massive traffic, and what other Black Hats are doing must remain underground to retain their effectiveness.
But what if I told you that you could discuss these exploits with me without paying my $500 an hour consulting fee? What if I told you there was a way to join in on the private, cutting edge discussions with some of the best Black Hats and web entrepreneurs in the world?
Would you be interested?
Because now you can . . .
Today is the official launch of the resource you’ve looked everywhere for but never found:
Normally what you get on forums are people who don’t know anything talking with people who don’t want to say anything. You can occasionally find amazing tips on some forums: but you have to dig through 400 crappy posts just to find one post that is useful. That becomes a huge time sink.
How are the SEO Black Hat forums different?
Quality: We’re not going to have any contests to see who can make the most posts. That just creates tons of crap that no one wants to read. Our focus is on quality over quantity. Our primary concern is with succinctly answering one question: “What works?”
Sophisticated: Many of the topics we discuss are very advanced and require a high level of technical or business acumen to appreciate.
Expert Discussions: The SEO Black Hat forums are not for everyone and they may not be right for you. If you are relatively new to SEO or building websites, then do not join the SEO Black Hat Forums: you will be in way over your head. There are plenty of newbie forums out there for you – this is not one of them. Our forums are for successful web entrepreneurs to develop strategies that drive more traffic and generate more revenues.
Access to Expert Advice and Discussions
We have both White Hat and Black Hat Experts that are already benefiting from new tool development, techniques, scripts and the sharing of ideas.
Some members you may already be familiar with include:
* CountZero from blackhat-seo.com (Black Hat)
* RSnake from ha.ckers.org (Web Security Expert)
* Dan Kramer from Kloakit (Cloaking Expert)
* Jaimie Sirovich from seoegghead.com (Token White Hat / SEO Geek)
There are several other members that you are certainly familiar with who are using handles for anonymity. We have others who are more focused on security, vulnerabilities, and coding. There are still more that you are likely unfamiliar with but are nevertheless web millionaires.
Databases – Large Datasets
If you want your sites to have massive amounts of unique content you need large data sets. The trading, discussion and posting of large data sets is going on right now on our forums.
Expired / Deleted Domain Tools
Want to use to use the same domain Tool that I used to get a Page Rank 6 site in the Gambling Space for just $8? This domain tool is available for members to use for free.
50% off on Kloakit – The Professional Cloaking Software
Scripts – Several useful scripts have already been posted – interesting thing you may not have thought of before are being discussed and developed.
Exploits and Case Studies: The really good stuff I can’t talk about on the SEO Blackhat Blog is being discussed on the SEO Black Hat Forums. Right now, some of the conversations include beating captchas, domain kiting, data mining, hoax marketing, XSS vulnerabilities as they relate to SEO, and much more.
Pricing: $100 per month.
The price will soon be rising significantly as more databases, hosted tools, scripts and exploits are added. However, once you lock in a membership rate it will never go up and you will continue to have access to everything.
So, if you think you’re ready for the most intense Black Hat SEO discussions anywhere, then here’s what you need to do:
1. Register at the SEO Black Hat Forums.
2. Go to the User CP and select Paid Subscription.
I’ll see you on the inside!
I used technorati today to find another site about seach engine spamming. Here’s what I found:
The script does the following things:
A - look for WP blogs in Yahoo
B - post a commentA) The script has a basic list of 100 most popular words in english language. It takes 2 random words, then queries Yahoo for WP blogs containing those words. Normally spammers take Google results. But I don’t wanna mess with my Biggest Friend.
B) Every post on WP has an ID. We don’t really wanna be bothered with extracting it… we just take a random number between 10 and 30, and try to comment on post with that ID.
Just select the text below, save it as commenter.php, put it on the server and you can start your career as a comment spammer.
In the spirt of putting more guns in the hands of children, we bring you more ways to create inbound links with cross site scipting.
Rsnake must have finished moving and unpacked his computers because he has created a Grease Monkey Detection Script for XSS (Cross Site Scripting).
Here’s the crappy redirect detection Greasemonkey script. I don’t recommend using it, because it sucks, but it was a good proof of concept.
Now granted a good chunk of these do not work, but that actually shouldn’t matter much. Without even testing, sending multiple possible attempts to Google, even if 80% of them fail, it’s not like you are giving anything up, you are sending valid links that probably have some custom error logic. It just looks like you are linking to a lot of custom error pages, potentially. So pruning the redirect attack list may or may not help.
SEO by spray and pray. Hat tip to v7n.
Do you want free backlinks? Does the Pope shit in the woods?
Boogybonbon has found a way to exploit the preview comment form to create backlinks from Movable type blogs.
From the post, MovableType preview button good for back links:
As long as the blog is not a MovableType 3.2/3.x the blog will give a nice URL that you can publish into a ping list and get indexed for back links. This is because the MovableType 3.x uses JavaScript to convert tags into a preview comment field and as we all know search engines cant see that.
Needles to say it only took me about 15 minutes to find 6 blogs with PR 5-8 and process the forms over to GET then post the URL’s into a couple ping sites.
Here’s how it works:
The preview comment button on movable type blogs uses the POST method but search engines require the GET method to index a URL. So, what you need to do is:
1. Download the firefox extension webmaster tools to convert the POST forms to GET forms.
2. Find Movable type blogs.
3. Open The “preview Comment” in a new window.
4. Convert the POST Form to a GET Form like this:
5. Fill out comment however you like.
6. Press preview comment.
7. Instead of producing a url like this:
http://www.baseballmusings.com/cgi-bin/mt/mt-comments-pinto.cgi
it will produce a URL like this (images used for formating purposes):
The links on the produced pages are NOT nofollow.
8. Now, you may want to use a service like tinyurl or a redirect to hide what you are doing (not required)
9. Ping that URL to the Search Engines in splog posts, guestbooks, or however you think best.
Pretty freaking cool, huh?
I’d like to add a quick reminder that you need sign up for the SEO poker Tournament by tuesday and email me your pacific poker username and website URL.
quadszilla (at) seoblackhat.com
What’s the Socializer?
The Socializer allows you to easily submit a link to several social bookmarking systems. Instead of having a link to each social bookmarking website, you have a single link to all of them!
I haven’t installed it yet, but I’m going to. It looks really cool.
Via Slashdot, Web Security posted a message about a cross site scripting vulnerability at Google:
Two XSS vulnerabilities were identified in the Google.com website, which allow an attacker to impersonate legitimate members of Google’s services or to mount a phishing attack. Although Google uses common XSS countermeasures, a successful attack is possible, when using UTF-7 encoded payloads.
One of the links in the slashdot submission is described by Phosphor3k as:
Someone [who] is trying to get their Pagerank up by submitting the story with a name of “Security Test” and linking to their shoddy website. The site has only a few links, no content, and it says the page is for sale. Will slashdot ever get their shit together and stop posting submissions with blatant pagerank-whoring links like this?
We covered spam sites getting slashdotted earlier . . . so it must not be that difficult. If you have a compelling and timely story, you can often include a link to one of your sites and get it passed the mods if the destination page looks legitimate. To me, this is the ultimate in link dumping.