16 ms·
How a Website Exploited Amazon S3 to Outrank Everyone on Google
- lapnitnelav 8y agoWhile cookie stuffing is nothing new in the wonderful world of Affiliate marketing, leveraging Amazon's force de frappe in this way is actually brilliant. Not that I condone it but the sheer ingenuity can be appreciated.
- chayesfss 8y agoYea I can imagine the dev who found this by accident like, holy shit did that just work!
- kaycebasques 8y agoI came into this post with a hunch that it would detail some weird social engineering stuff and it did not disappoint. What a weird, interesting world we live in.
- kaycebasques 8y agoAlso, this quote gave me a good chuckle. > Imagine Usain Bolt looking back as he runs the 100 meter dash and seeing you covered in sweat, screaming up behind him. Imagine the look on his face. That’s my face when I saw this page went from total obscurity to top ranking for “g2a discount code” in one month and generating an estimate 30,000+ visitors to that one page. Really effective use of imagery. I love how he directs your attention to think about Bolt’s face, which is easy to imagine.
- jiveturkey 8y agohow is this social engineering? genuine question.
- kaycebasques 8y agoI’m referring to the explanation of what seems to be called cookie stuffing (based off other comments in this thread). Most of you probably already know about this, but it was news to me and very satisfying to learn why those shitty coupon sites exist. The main idea of the post doesn’t seem to be related to social engineering, though. Sorry for the confusion, I should have clarified.
- ryandrake 8y agoIt seems less social engineering and more taking advantage of search engine stupidity (Domain Authority) to do run or the mill black hat SEO. I mean seriously, I would have thought a multi-billion dollar search engine would be more sophisticated than “durr, the domain has amazonaws in it, therefore it must be legit!”
- kaycebasques 8y agoI'm just going off of this Wikipedia definition of social engineering: > Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. The psychological manipulation in this case is getting people to click a button because they think that it will show them a coupon (and therefore save money), when in reality it does no such thing and instead puts a cookie in their browser.
- scrollaway 8y agoBy your version of the definition, asking your friend to pass the butter is social engineering. The definition you copied is vague but includes the key phrase "in the context of information security". The coupon code sites are just scamming people by wasting their time (and primarily, scamming the retailers). It's essentially just fraud. If this were in an infosec context (clicking something that pretends to be legitimate in order to gain some benefit), it'd be closer to phishing.
- jiveturkey 8y agonot the top link in any of the demo'd searches, so clearly the title is false. technically. still it's fascinating. > Seth Kravitz is the CEO of PHLEARN, the world’s #1 Photoshop & Lightroom training company online wow. i guess CEOs of any online company have to have deep deep understanding of SEO these days. and what better SEO than blogging about things unrelated to your company! as we just saw a few days ago from 3byte.
- iagovar 8y agoFuck, im done :/
- techaddict009 8y agoSo in which niche you were cashing the cow in? :P
- iagovar 8y agoISPs (not the US)
- techaddict009 8y agoCan you share more how exactly these pages rank? Just making static page doesn't rank. (I shared this post with SEO community and few people commented there so) Along with making static page any other things need to be done? Like Spam Links, Social Signals, PBN Links, Guest Posts, Forum Links, etc.
- iagovar 8y agoJust normal linkbuilding. This guy didnt catch any link with ahrefs but I was unable to rank properly without them. When I say links, I mean more than just links for getting it crawled. So you still have to spend money/effort in it, sorry. Also since it's been published here, any edge that you could get is over. It's going to be badly abused.
- kapauldo 8y agoYeah this is brilliant.
- lifeisstillgood 8y agoThe coupon thing seems crazy - Walmart must be spending real money to reward sites that actually did not provide a coupon. i mean i know it's all about consumer surplus, but all walmart knows is that someone on the internet wanted to get a discount, did not get it, and now walmart pays random SEO cash. They lose margin, the buyer is frustrated cos they paid full price, and walmart knows nothing about surplus because the client paid full price - no differentiation no price signal. how is walmart winning here?
- fabricexpert 8y agoWalmart only pays if they make a sale, so long as the commission isn't greater than their margin it's just a customer acquisition / marketing cost that drives sales if they have it and takes them away if they don't. This is like saying "Most people who watched the TV ad didn't buy anything, how is Walmart winning?" The age old saying is that you know half of your marketing budget is wasted, you just don't know which half. It still applies now even if you can track users.
- lifeisstillgood 8y agoBut it's not a channel. if i turn up at the till with coupon clipped from the tv guide, then putting coupons in the tv guide is a viable channel to reach me if i turn up with a cookie from whichever SEO happened this week to be on top for "gardening gloves", but there is no legal coupon just a cookie, then what has walmart learned? that google is a channel ? it's too big to be useful
- southerndrift 8y agoOr Walmart makes a profit because they dupe the real referers. They can identify and cancel those SEO accounts and deny payout. Meanwhile, the real advertisers have lost their cookie and don't get their deserved payout.
- ComputerGuru 8y agoI don’t know. The biggest shady coupon sites have been around for a long time now.
- Rjevski 8y agoI am more surprised that this kind of coupon trickery still pays off and the retailers are burning money on it. The way I see it, you only search for coupons once you see a product at a retailer and you want to buy it (or even once you already have a shopping cart built up, and are on the checkout form where the coupon field is). So the retailer already acquired you as a customer, and you're ready to checkout. Most likely you'll end up checking out anyway even if you don't find any valid coupons (which is what's currently happening, since most coupons don't work anyway). So why are retailers still paying out affiliate revenue in this case? They have the customer already. This shady affiliate doesn't bring them anything they didn't already have. They can easily fix this by only paying out affiliate revenue for actual, legitimate affiliates, those that brought you a brand new customer. If the user already spent time browsing your website and built up a shopping cart, don't pay out affiliate revenue even if they do end up clicking on an affiliate link after.
- stirlo 8y agoOne of Australia’s largest online retailers agrees with you. https://venturebeat.com/2013/08/12/the-big-ugly-affiliate-marketing-scam/ https://venturebeat.com/2013/08/12/the-big-ugly-affiliate-ma...
- ryandrake 8y agoCouldn’t the retailer just look up when the cookie was set? If it was set during some window before the user had items in their cart, pay the affiliate. If it was set after, or long in the past, don’t pay.
- unreal37 8y agoThen it's a game of trying to find ways to not pay your affiliates. Do you want to be the retailer than gets known in the affiliate space for trying to find loopholes not to pay what they said they would? People would stop promoting your site. You might as well shut down your affiliate program if you're going to not pay your affiliates sometimes.
- 8y ago
- techaddict009 8y agoThis concept is called the leeching and ranking. In this, mostly Google Sites & AWS S3 is preferred as a source by the leechers. Mostly used by coupon and movie download sites. Finally, someone has openly spoken about it, instead of exploiting it a bit more!
- slig 8y agoI'm surprised Google didn't kill Google Sites yet.
- giancarlostoro 8y agoGive it time... Sadly.
- techaddict009 8y agoGoogle has tried to but hasnt killed it completely. Like it has reduced features on it.
- crazygringo 8y agoWhat are you talking about? They launched a totally new version a little less than two years ago, and new features keep coming so they seem to be continuing investment in it... https://www.blog.google/products/g-suite/totally-rebuilt-sites-customer-tested/ https://www.blog.google/products/g-suite/totally-rebuilt-sit...
- A7med 8y agothat's clever
- Belphemur 8y agoUsing another company (amazon in this case) to do your SEO for you. This is so phishy. Doing a landing page on Amazon S3 and having all the link redirecting to your real website. I'm starting to wonder if shady SEO marketing companies aren't already doing this to promote their "clients". I hope the Google SPAM team we'll do something about it.
- phreack 8y agoIt's been going on for ages, they call it 'parasiting' and it's awful but it's worked for years
- gammateam 8y agolollll that's hilarious now everyone's going to try that and it stops working but then people are going to start naming their s3 buckets amazon-
- deleted 8y ago[deleted]
- codezero 8y agoI assume they got indexed by using Google's webmaster tools to trigger a crawl.
- techaddict009 8y agoNo need for Webmaster tools to get indexed. Share it on G+ or any webpage which is indexed in Google your site will get indexed pretty soon.
- slig 8y agoYou can only trigger a crawl on your own verified property, AFAIK.
- giarc 8y agoIt's not the indexing that's the trick. That means nothing in this context. The interesting part is how a site with no backlinks etc can outrank a ton of other sites. The running hypothesis is that google treats all aws links as being owned/operated by Amazon.
- bhartzer 8y agoThis is just pointing out a site that's ranking--the title of the post doesn't go with the content of the post. The "how" isn't revealed. Regardless, most likely there are links involved, and there actually be canonical tags involved, as well. If there are links involved they're most likely hiding them from link crawlers like ahrefs and Majestic.com.
- deleted 8y ago[deleted]
- dazc 8y agoThe amazon domain is the 'how'.
- bhartzer 8y agoThat's what we would like to believe, but the concept of domain authority doesn't exist. (Just because a page is on a certain domain name it should rank... is false). I'd put my bet on links (that are hidden), link ghosting, or cross-domain canonical tags. It's not "just because it's on the Amazon domain". If domain authority existed, we'd see sites on Google sites, Business.site rank--and they don't.
- theseanstewart 8y ago> the concept of domain authority doesn't exist. Is that really the case now? It's been 3-4 years since I was involved in SEO, and it was very much a thing back then.
- bhartzer 8y agoActually, it's never been "a thing". Domain Authority is just a concept that was created by Moz--a metric. This is an interesting read: https://www.searchenginejournal.com/domain-authority/246515/ https://www.searchenginejournal.com/domain-authority/246515/ "No SEO will ever point to a Google patent or research paper to justify the idea that a Site/Domain Authority exists. Wikipedia has published a page about Domain Authority and the footnote links do not cite a single research paper or patent by Google. Not one. According to the footnotes, Wikipedia’s information is largely based on blog posts by SEOs. There are no links to anything official from Google."
- matthewaveryusa 8y agoI'm trying to understand how this works: the s3 page has all links go to promocode.org https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/index.html https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/in... When you click on that you get redirected to promocode.org where you get re-prompted to click on the promo code and that's where the cookie promo gets tacked on the walgreens website. I understand that amazonaws.com is a highly-ranked domain. What part of this process makes this particular s3 webpage rank up in search algorithms though? At the end of the day don't you need lots of _direct_ inbound clicks and links to this specific s3 page for it to rank higher? The only way I see this working is if _indirect_ clicks of the entire domain count towards the ranking of this specific page -- that doesn't seem right though. edit: looks like the paragraph above describes the concept of "domain authority" so that's probably the answer
- md224 8y ago> What part of this process makes the s3 webpage rank up in search algorithms though? No idea. The article basically ends with "I'm not sure exactly how this happened so I'm going to talk to some experts". A bit of a letdown, tbh. I was waiting for the big reveal!
- superasn 8y agoI'm not sure either but it looks something to do with domain authority as the pages are hosted on amazon s3 and the domain is related to amazon maybe it makes Googlebot think the pages are affiliated to amazon so it ranks them higher (just like articles on wikipedia.org rank higher with less effort). This is all conjecture though because I'm not an expert so maybe somebody can correct me or add to it.
- rjpr 8y agoProbably because Google is treating all s3.amazonaws.com links as being the same authoritative site, so they see each of these coupon sites as just a page of s3.amazonaws.com and therefore the site gets the link 'juice' from the root s3.aws domain. Each page of a site doesn't need a ton of links to that specific page to rank, just links to the site in general (site being root link plus subdomains). That's typically why blogspot-type services give you a subdomain, and not a page on their main domain. It's been known about in SEO circles for a while[0], will be interesting to see if things change in the next major Google update. [0] https://www.blackhatworld.com/seo/how-to-get-backlinks-from-amazon-aws.1025436/ https://www.blackhatworld.com/seo/how-to-get-backlinks-from-...
- qwerty456127 8y ago> Since most of the coupons you find on these pages don’t work, you may have wondered why do these coupon sites even exist? Their primary goal has been and will always remain to attach a browser cookie to your web browser I really wonder why deleting all the cookies for a given website as soon as you close it isn't the default behavior and not even a built-in option in web browsers. I use Vanilla Cookie Manager in Chrome to make it work this way.
- donald123 8y agoIt's called incognito mode.
- qwerty456127 8y agoAFAIK incognito mode doesn't let you whitelist certain websites you actually want to save cookies.
- rifung 8y ago> I really wonder why deleting all the cookies for a given website as soon as you close it isn't the default behavior Probably because users would find it annoying to have to log in to all their websites again. The sad reality is there's not much point in having privacy features if nobody uses your browser so there is a balance to be struck.
- quickthrower2 8y agoI feel an experiment coming on...
- vuln 8y agoAm I the only one that thinks this is 'paid prioritization'?
- sdk959 8y agoA bit off topic, but if you wanted to get better savings (aside from coupons), try adding your products to a cart and leaving it alone for 2-3 days. Often, online places will offer you a significant discount by having items in the cart and not checking out. It's their way of getting you back in even if it means selling at break even prices.
- pz1 8y agoI am the hacker I an the game master
- CodeSheikh 8y agoSearch for a coupon in one browser and buy the product in another to keep these "marketers" at the bay.
- QuantumGood 8y agoA modern version of the old parasiting .edu hack.
- tootahe45 8y agoWouldn't it just be that https://s3.amazonaws.com https://s3.amazonaws.com is linked on tens/hundreds of thousands of websites and they're capitalizing on this for SEO value, rather than 'Domain authority'?
- hex64 8y agoLet's decompose what is going on when you click on one of these pages : For instance : https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/index.html https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/in... It's a page with fake coupons links When you click the "show coupon" boutton, two things happen 1. A javascript "click" event is triggered (in coupon.js) and executes : window.open(https://www.promocodefor.org/promo/walgreens/walgreens-photo-coupon/c833699cf9ddea03/enjoy-50-off-enlargements-and-posters/?expanded=1 https://www.promocodefor.org/promo/walgreens/walgreens-photo...) This opens a new tab at this url, this page shows the fake coupon code. 2.Since the button is a <a> tag with href="https://www.promocodefor.org/go/pcfc833699cf9ddea03" https://www.promocodefor.org/go/pcfc833699cf9ddea03", the current tag navigates to this url Then you follow 7 redirect redirects (code 302) to pages owned by https://skimlinks.com https://skimlinks.com who redirects to pages owned by https://www.conversantmedia.com https://www.conversantmedia.com who finally redirect to https://photo.walgreens.com/store/prints?tab=photo_Promo1 https://photo.walgreens.com/store/prints?tab=photo_Promo1 It's basically an affliate link to walgreens. The question is how did https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/index.html https://s3.amazonaws.com/walgreens-photo-coupon/walgreens/in... rank so high in google ? Just because it's hosted on amazon doesn't make sense. There is a trick that we don't know. I think it's hosted on Amazon S3 juste because it's very cheap hosting, since the site is a single .html file
- z3t4 8y agoThis works because Google rank based on domains, not URL's. All link power counts towards the domain, also boosting other pages on that domain.