Canonical Pollution Attack

Details

Vector type:
Copy Attack
Risk level:
Low
Impact level:
Low to Moderate

This is another simple one. You copy your target’s content, including markup and styling, then you modify the content to include “Safe-Search Trigger Terms,” and canonicalize the newly created page to the one you took the copy from. The general principle here is to get Google to consolidate the content and attribute your changed version to the original, thus causing Safe Search problems and reducing your victim’s SERP visibility.

(Even if the pollution fails, they may still succeed with a Canonical Confusion attack.)

Defense

Not only is there no defense against this type of attack, it’s also basically undetectable, since it leaves absolutely no detectable footprint anywhere outside the Google systems.

Once again, the only option you have is to make sure your site is popular and visible, so as to avoid the Canonical Pollution from rubbing off on it.


Leave a Reply

Your email address will not be published. Required fields are marked *