Later archive addition
Google XML Sitemap Authentication Bypass
The researcher found that Google's unauthenticated sitemap ping endpoint could be made to trust an attacker-hosted XML sitemap as belonging to another site. Malicious hreflang and indexation directives then transferred search authority to attacker pages, allowing manipulation of high-value rankings without owning the victim domain.
Record
- Researcher
- Tom Anthony
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tom Anthony, first published at the original source. Preserved copies are kept so the citation survives its host.