Spam Content on Website, Help! What to Do?

Laptop surrounded by trash.

ISAP vulnerabilities are making headlines across the cybersecurity world. Your WordPress site might be in the crosshairs, but luckily you can avoid this and protect your business.

As a hosting provider, Seravo has also encountered this vulnerability and malicious content. In this article, we explain where the vulnerability stems from and what steps you should take if suspicious content appears on your site. By taking proactive measures and acting quickly, you can protect your site’s functionality and your brand reputation!

What is ISAP?

ISAP stands for Internal Site Search Abuse Promotion. In an ISAP exploit, your site’s internal search function is (ab)used to spread malicious content and spam so that the unsolicited content appears in search engine results.

Attackers attempt to abuse search engine results and indexed content through various methods, and ISAP is but one technique. Spam content is usually added to a site in a way that avoids detection by the site owner or user. It could be called a “black hat SEO” technique: with ISAP, hackers essentially gain free advertising space for content that supports their criminal activities.

How ISAP Works

Modern websites and content management systems (such as WordPress, Drupal, HubSpot, or Shopify) offer visitors a search field to look through the site’s content. When a user performs a search on your site, it often generates a dynamic search results page and a web address similar to this:

yourawesomesite.org/search?q=searchterm

How spam content gets added to your site:

  1. Search field abuse: An attacker enters search terms into your site’s search field. The search contains unwanted information, such as spam links, or advertisements for illegal services.
  2. Dynamic content creation: The site creates a search result page that repeats the entered search term, even if not a single relevant search result is found on the site itself. Depending on the site settings, the search feature may not filter or censor these unsuccessful searches.
  3. Search engines index the searches: Search engines (such as Google or Bing) find these generated search results and their URLs, and index them.
  4. Reputation hijacking: Because your site has a good reputation and a trusted domain, search results featuring your site’s name appear on Google, containing spam content in their titles or descriptions.

As a result, the attacker gets “free search engine visibility” at the expense of your site, even though no one has actually breached or hacked into your site at any point.

ISAP Harms Your Site and Your Business

Even though this type of search field abuse does not directly give an attacker access to your server files or database, it has serious consequences for your search engine visibility (SEO), among other things:

  • Drop in search engine rankings: Google, for example, may penalize the site for spreading spam and drop the search ranking of your legitimate pages.
  • Brand damage: Your customers might land on your site via Google and see illegal content or links directing to shady websites under your site’s domain.

Additionally, indexing search result pages unnecessarily consumes server resources as search engine bots crawl through them, even though the content is unwanted and uninvited.

How to Fix the ISAP Vulnerability

Because ISAP exploits the site’s own native features, the most permanent solution is made within the website’s own settings. We recommend checking the following points:

1. Prevent Indexing of Search Result Pages (Recommended)

A site’s internal search result pages generally do not need to appear in search results on Google or other search engines. You should change these settings so search engines do not index those pages:

  • Add an HTML meta tag to search result pages. If you use an SEO plugin, check its settings.
    • These plugins usually manage the contents of the robots.txt file in WordPress.
      • If you do not use a plugin, take a look at how your active theme handles the creation of search result pages.
  • Add a rule to your site’s robots.txt file that disallows the indexing of search result pages (e.g., Disallow: /?s= or Disallow: /search/).
    • Read more about the robots.txt file in WordPress.
    • Note that search results can still end up indexed by search engines in other ways, even if your own site has disallowed their indexing.

2. Handle Empty Search Results Properly

  • If a search yields no results, ensure your site does not generate a dynamic page that repeats arbitrary text in its headings.
  • Alternatively, return an appropriate HTTP status code (e.g., 404 Not Found) for empty search URLs so search engines do not index the page.

Seravo Protects Your WordPress Site

Security and good cybersecurity practices are a joint effort. Seravo protects its hosting customers’ sites in multiple ways, and our service includes features such as:

  1. WAF Firewall Rules: We’ve configured our Web Application Firewall (WAF) to detect and block common attack attempts.
  2. Security Scans: Our automated scanners review sites daily. We notify our customers if anything suspicious is found. Get to know our unique security guarantee.
  3. Isolated Environment: Every site in our hosting service is isolated, meaning a vulnerability found on one site cannot directly affect other sites or web hosting accounts on the server.
  4. Other Protections: For example, the WordPress login page is protected against brute-force attacks, and our on-call engineers proactively respond to denial-of-service (DDoS) situations and other trending threats.

Read more about security in Seravo’s premium hosting for WordPress on our security FAQ page.

Expert Help with WordPress and Security

Cybersecurity can sometimes feel complex. As Seravo’s customer, you will not be alone with these issues. Wondering about your site’s security? Need technical assistance related to site maintenance? Our customer service provides information and support to help you forward!

Get in touch with us and submit a support ticket and let’s check your site’s status. The know-how of our WordPress experts is free, and we process support tickets quickly, usually within the same working day.

Be sure to check out the instructions in our knowledge base at help.seravo.com!

Seravo – Premium Hosting for WordPress

Seravo is a premium hosting service providing a fast and secure server environment for your WordPress site. Our service includes everything you need to maintain your WordPress.

Learn more about our features and order today!