<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: MS Live Search hitting web sites with fake referer information</title>
	<link>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/</link>
	<description>Contempt Is King.™</description>
	<pubDate>Fri, 21 Nov 2008 03:54:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>

	<item>
		<title>By: MSN Live Search Spam BOT Cloaked referrals - Yack Yack SEO</title>
		<link>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-44</link>
		<author>MSN Live Search Spam BOT Cloaked referrals - Yack Yack SEO</author>
		<pubDate>Sat, 21 Jun 2008 09:23:49 +0000</pubDate>
		<guid>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-44</guid>
		<description>[...] MS Live Search hitting web sites with fake referer information [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] MS Live Search hitting web sites with fake referer information [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Everfluxx</title>
		<link>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-23</link>
		<author>Everfluxx</author>
		<pubDate>Sat, 03 Nov 2007 09:59:19 +0000</pubDate>
		<guid>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-23</guid>
		<description>Hi Stefano! :)

I'm still not sure this is an automated check for referer-based cloaking. The same IP has also been requesting linked CSS and JS files... Take a look:

&lt;code&gt;65.55.165.15 - - [02/Nov/2007:02:02:58 +0100] "GET /requested/url.html HTTP/1.0" 200 65429 "http://search.live.com/results.aspx?q=keyword&#038;mrt=en-us&#038;FORM=LIVSOP" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:02:59 +0100] "GET /css/main.css HTTP/1.0" 200 2832 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:02:59 +0100] "GET /js/prototype.js HTTP/1.0" 200 96046 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:03:00 +0100] "GET /js/scriptaculous.js?load=effects HTTP/1.0" 200 2152 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:03:01 +0100] "GET /js/effects.js HTTP/1.0" 200 31969 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:03:01 +0100] "GET /js/lightbox.js HTTP/1.0" 200 23825 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"
65.55.165.15 - - [02/Nov/2007:02:03:02 +0100] "GET /css/lightbox.css HTTP/1.0" 200 1637 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"&lt;/code&gt;

If the guys at MS really wanted to check for cloaking, why issue an easily recognizable (and, thus, cloakable!) referer in the first place?

I don't think this was intentional, after all.

I think the referer with the "FORM=LIVSOP" parameter might have been &lt;strong&gt;leaked&lt;/strong&gt; by an internal interface used by Live Search's quality raters instead (remember, msndude said this was a "quality check")... Maybe (I'm guessing) "LIVSOP" = "LIVe Search OPerator [Console]"? ;)

Just a thought...</description>
		<content:encoded><![CDATA[<p>Hi Stefano! <img src='http://www.everfluxx.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;m still not sure this is an automated check for referer-based cloaking. The same IP has also been requesting linked CSS and JS files&#8230; Take a look:</p>
<p><code>65.55.165.15 - - [02/Nov/2007:02:02:58 +0100] "GET /requested/url.html HTTP/1.0" 200 65429 "http://search.live.com/results.aspx?q=keyword&#038;mrt=en-us&#038;FORM=LIVSOP" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:02:59 +0100] "GET /css/main.css HTTP/1.0" 200 2832 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:02:59 +0100] "GET /js/prototype.js HTTP/1.0" 200 96046 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:03:00 +0100] "GET /js/scriptaculous.js?load=effects HTTP/1.0" 200 2152 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:03:01 +0100] "GET /js/effects.js HTTP/1.0" 200 31969 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:03:01 +0100] "GET /js/lightbox.js HTTP/1.0" 200 23825 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"<br />
65.55.165.15 - - [02/Nov/2007:02:03:02 +0100] "GET /css/lightbox.css HTTP/1.0" 200 1637 "http://www.example.com/requested/url.html" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)"</code></p>
<p>If the guys at MS really wanted to check for cloaking, why issue an easily recognizable (and, thus, cloakable!) referer in the first place?</p>
<p>I don&#8217;t think this was intentional, after all.</p>
<p>I think the referer with the &#8220;FORM=LIVSOP&#8221; parameter might have been <strong>leaked</strong> by an internal interface used by Live Search&#8217;s quality raters instead (remember, msndude said this was a &#8220;quality check&#8221;)&#8230; Maybe (I&#8217;m guessing) &#8220;LIVSOP&#8221; = &#8220;LIVe Search OPerator [Console]&#8221;? <img src='http://www.everfluxx.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Just a thought&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefano Gorgoni</title>
		<link>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-22</link>
		<author>Stefano Gorgoni</author>
		<pubDate>Fri, 02 Nov 2007 20:30:06 +0000</pubDate>
		<guid>http://www.everfluxx.com/ms-live-search-hitting-web-sites-with-fake-referer-information/#comment-22</guid>
		<description>well, i think you spotted the point. referer-based cloaking is maybe  the hardest cloaking to detect. 

so, adding a fake referer can help search engines to find it out... :)

am i wrong?</description>
		<content:encoded><![CDATA[<p>well, i think you spotted the point. referer-based cloaking is maybe  the hardest cloaking to detect. </p>
<p>so, adding a fake referer can help search engines to find it out&#8230; <img src='http://www.everfluxx.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>am i wrong?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
