HomeSecurityNew hacking trick: Attackers use Google Search Console

New hacking trick: Attackers use Google Search Console

Attackers Use Google Webmaster Tools to Hide Hacked Websites – After hacking your website, hackers will take control of your Google Search Console account to hide their “infections”.

A new hacking trick has been discovered by Sucuri, with which attackers infiltrate a website and then take control of the Google Search Console account (primarily Webmaster Tools) to hide and prolong their "infections".

New hacking trick discovered: They use Google Search Console
A new hacking trick has been discovered by Sucuri, with which attackers infiltrate a website and then take control of the Google Search Console account (primarily Webmaster Tools) to hide and prolong their "infections".

What we knew as Google Webmaster Tools, was renamed Google Search Console in May 2015, and offers website owners tools to optimize their search engine rankings by analyzing traffic, submitting updated sitemaps, and even detecting spam campaigns or malicious code on their domains.
It is a crucial tool for all webmasters interested in SEO and is widely used by almost all developers.

Applicants register with their own Google Search Console account

According to Sucuri staff, the real problem lies in how the service was designed to work. Because running a website typically requires a team of people, from developers to SEO specialists, as well as marketers to salespeople, Search Console allows multiple users to register as a website owner.

The simplest method is to add an HTML file to the website's server that Google Search Console uses to authenticate users. The problem with this is obvious. If a hacker gains access to a site, they can easily import their own HTML authentication file into the server's FTP and gain access to Search Console.

Once a hacked website is verified, attackers can use it to submit new spammy pages to Google from a verified source, get statistics on their campaigns, receive notifications when their malicious code is detected by Google, and update sitemaps to hide their malicious attacks for even longer.

Of course, Google sends email alerts whenever a new user is added to Search Console. But if a domain is unclaimed or the other owners ignore these alerts, attackers could easily go unnoticed, or they could also remove the HTML files used to validate legitimate owners from the site, effectively locking them out of the site.

And to tell the truth, it's pretty easy to ignore these messages. Because developers and webmasters typically handle dozens of websites, these notifications are usually ignored or filtered out of the inbox into a special folder.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS