PageRank Bleeders Target AARP Website

LOS ANGELES — The recently reported hack of the AARP.org website demonstrates an increasingly sophisticated approach to traffic manipulation and malicious user-system compromises — and once again, Internet porn takes the blame.

You see them in user communities all over the Internet: spam posts on blogs and boards; fake user profiles or "nicks" (short for "nicknames"); and seemingly inappropriate or misplaced comments and postings on every venue possible — and they all share at least one common goal: to get viewers to click through into their traffic stream and then on to their targeted destinations and beyond…

It's not just you, the individual web surfer that is increasingly being targeted as a source of clicks, however; but Google and other search engines that spider website content, too.

In the ceaseless battle for improved PageRank (PR; a means by which Google orders its search result listings), some promoters have turned to so-called "comment spam" on blog posts and automated message board bots that seek to place keyword-laden back-links on "authority sites" that enjoy — and pass on through these outbound links — a higher PR.

This process can improve the results that the sites being promoted enjoy from their other search engine marketing strategies; and often causes no more annoyance to the victimized website than having an erroneous posting that a moderator or automated tool must delete.

Far more troubling are the more malicious attacks that seek to infect the user's system with malware, as seen in the AARP example; where a coordinated, multi-prong attack that combined automated blog spamming, PR bleeding and automated redirects to porn sites via a JavaScript embedded into profile page listings, added a Trojan drop as well.

"First, hackers found vulnerabilities in AARP.org's user profile functionality, allowing them to post JavaScript redirect code and HREF links to porn sites," Jeremy Yoder of MX Logic, blogged. "Second, hackers employed bots in a massive campaign to submit blog comments containing links to the hacked AARP.org user profiles."

The AARP website is apparently driven by an in-house content management system (CMS) that is lacking in basic security precautions.

"It appears to be a custom system that's missing some baseline-level security capabilities," Yoder opined. "This site is accepting JavaScript code submissions, which are something that most off-the-shelf content management systems would have no trouble blocking."

"There has been a considerable increase in the use of comment and profile spam to promote pornographic or phishing sites in search engines," Yoder added. "This one was particularly notable because of the precise coordination of the attack, the exploitation of Web 2.0 functionality and the SEO motivation."

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Brazil Invites Public Input on AV Guidelines

Brazil’s National Data Protection Authority (ANPD) on Friday launched a public consultation on developing guidelines for age verification mechanisms under the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

Paysite Confidential: Inside the Creator Economy's Shift Toward Ownership

For years, the adult industry’s creator economy has been defined by platforms — powerful engines of discovery, monetization and scale that reshaped how performers connect with their audiences.

Senator Urges DOJ to Crack Down on 'Obscenity,' Attacks OnlyFans

U.S. Senator Jim Banks of Indiana this week urged Acting Attorney General Todd Blanche to reestablish the Department of Justice’s defunct Obscenity Prosecution Task Force in a letter that targets OnlyFans while repeatedly conflating “obscenity” with legal adult content.

UN Experts Urge US, Canada to Prosecute Aylo, Others for 'Exploitation'

GENEVA – The United Nations Office of the High Commissioner for Human Rights (OHCHR) has issued a press release in which two U.N. special rapporteurs, cited as experts, accuse Aylo and other companies of complicity in sexual exploitation.

Kickstarter Revokes New Rules Banning Fundraising for Adult Content, Products

Crowdfunding platform Kickstarter announced Tuesday that it has reversed its recent decision to impose new “Mature Content” rules banning projects that involve adult content and sextech.

Report: Irish Justice Minister Seeks UK-Style Ban on 'Extreme' Content

Ireland’s justice minister plans to introduce legislation criminalizing possession and distribution of “extreme” pornography, according to a report by the Irish Independent.

New Kickstarter Rules Ban Fundraising for Adult Content, Products

Crowdfunding platform Kickstarter has posted new “Mature Content” rules banning projects that involve adult content and sextech.

WebGroup Czech Republic Settles Florida AV Suit, Will Pay $1.2 Million

WebGroup Czech Republic (WGCZ), the parent company of XVideos, XNXX, BangBros and GirlsGoneWild, has settled a lawsuit filed by the state of Florida over those sites’ alleged failure to age-verify Florida users before allowing access to adult content.

AEBN Publishes Popular Searches for March, April

AEBN has published the top search terms for March and April from its straight and gay theaters in all 50 states and the District of Columbia.

Ofcom Investigates Two Sites Over Possible AV Violations

U.K. media regulator Ofcom on Wednesday launched investigations into two adult sites as part of its age assurance enforcement program under the Online Safety Act (OSA).

Show More