Web Hack List

Later archive addition

Google XML Sitemap Authentication Bypass

The researcher found that Google's unauthenticated sitemap ping endpoint could be made to trust an attacker-hosted XML sitemap as belonging to another site. Malicious hreflang and indexation directives then transferred search authority to attacker pages, allowing manipulation of high-value rankings without owning the victim domain.

Record

Researcher
Tom Anthony

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tom Anthony, first published at the original source. Preserved copies are kept so the citation survives its host.