Calendar Of Updates: Short URLs, big problems - Calendar Of Updates

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Short URLs, big problems

#1 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 05 June 2009 - 05:41 PM

Quote

Short URL services are becoming increasingly popular among social networks, especially on Twitter. When you have to limit your message to just 140 characters, every character becomes important, and posting links to searches on Google or news websites can rapidly fill an entire Twitter message.

Of course, for every problem there is a solution, so what URL shortening services like TinyURL, Is.gd or Bit.ly are doing is to offer for free short URLs that redirect to the longer ones. Everything might seem great until the moment you start thinking about security, and several problems come to my mind.

Social engineering is made easier. The user doesn’t really see the URL of the page he’s going to, but just the shortened version, which usually doesn’t offer any clue of where the destination page is hosted. An attacker can say he’s linking to “nice pictures with bunnies”, but instead sending the user to a website hosting malicious content.

The reliability is questionable.

Trust can be a problem.

Security concerns are being raised by these URL shortening services, and I am very glad to see the media also starting to notice them and raise the security awareness level throughout their readers: AP recently posted an article about short URL services that also touches on the security problems.


http://www.viruslist...logid=208187741

Yup it is a big PROBLEM and it’s why I don’t use URL redirection but if I have to, I will use ShuURL or Steven Burn’s URL redirection service called, sURL http://www.it-mate.co.uk/?sec=sURL because with sURL, you can’t redirect a link if it’s known bad site or listed in hpHOSTS database while with ShuURL, you get the Web of Trust rating before you decide to proceed with the redirected link.

Related article on Short URLs or URL redirection:

Is URL Redirection services safe to use?
Use ShuURL with Web Of Trust to view or create a short URL

#2 User is offline   hewee Icon

  • hewee
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Member - MVC
  • Posts: 4,857
  • Joined: 12-May 04

Posted 05 June 2009 - 08:22 PM

There is for Firefox some add-ons to help you out.

Long URL Please

Quote

Replaces short urls with the originals so you can see where links actually link to.


#3 User is offline   E Pericoloso Sporgersi Icon

  • Sir E of The Knights Errant
  • PipPipPipPipPip
  • Group: Member - MVC
  • Posts: 727
  • Joined: 11-May 07

Posted 06 June 2009 - 04:50 AM

View Posthewee, on Jun 5 2009, 10:22 PM, said:

There is for Firefox some add-ons to help you out.
Long URL Please

Quote

Replaces short urls with the originals so you can see where links actually link to.

Hey, hewee, thanks for that link.

I usually refuse any kind of toolbar or add-on. But this seems a very promising FireFox add-on.

It might convince me to keep it active. It's certainly worth a trial run.

#4 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 06 June 2009 - 06:51 AM

View Posthewee, on Jun 5 2009, 12:22 PM, said:

There is for Firefox some add-ons to help you out.

Long URL Please

Quote

Replaces short urls with the originals so you can see where links actually link to.

TY for mentioning this hewee! I don't use FF much though but will remember that add-on. It will help one of the concerns in using Short URL.

:)

#5 User is offline   hewee Icon

  • hewee
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Member - MVC
  • Posts: 4,857
  • Joined: 12-May 04

Posted 06 June 2009 - 03:28 PM

E Pericoloso and Donna you are both welcome.


Plus I was thinking there was another one out there I seen but I could not find it.

I know there are so many short URL add-ons it is a wonder we do not see more short renamed links out there.
Sure most may be good links but it is the bad ones we need to know about that can get us into trouble.
I hate it when your at a forum and they post a link and you trust the person but it is that tiny URL link because I block it with my hosts file.
Also I think any good Forum that is around to help and protect people and there computers should block out the tiny URL links so they can not be posted.

#6 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 06 June 2009 - 03:45 PM

Good idea hewee. We'll ask our fixer/coder to consider that if we will see people posting short URL here that can pose risk to others. :)

#7 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 07 June 2009 - 04:08 PM

I just saw this blog entry in ZoneAlarm blog:

Quote

ZoneAlarm blocks a web site that you want to visit. For example, some users have noted that ZoneAlarm blocks them when they go to TinyURL.com. Why would ZoneAlarm do this, and what do I do if that happens?

Spyware has occasionally been downloaded from TinyURL.com or a partner site (TinyURL often redirects users to other sites). To protect you from this threat, ZoneAlarm warns you about it and blocks that specific Web site. But people might still want to use TinyURL.com anyway – after all it’s a useful tool for posting short urls on Twitter. Well, you still can.

http://blog.zonealar...te-spyware.html

#8 User is offline   MysteryFCM Icon

  • Phishing Phanatic
  • PipPipPipPipPip
  • Group: Member - Experts
  • Posts: 533
  • Joined: 04-February 04

Awards Bar:

Users Awards

Posted 07 June 2009 - 04:18 PM

Cheers for the ref Donna :)

Just an FYI, the sURL homepage is at http://surl.co.uk

I know it's in dire need of re-design and re-write - I am hoping to get some time to do it within the next few months :)

#9 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 07 June 2009 - 04:25 PM

Thanks for the homepage of sURL. Was looking for it when I posted and I run out of time (dogs need to go out for a walk and they are pulling me!) :D

I like the option - Are you nuts? LOL but you know I don't use URL redirection but will click only on shortened URLs if it's using your service or ShuURL. And I saw one person posted a comment in my blog... with another short URL service that they said will check for safety/security:
http://msmvps.com/bl...s.aspx#comments

Quote

Safe.mn (http://safe.mn/) addresses the two main criticisms to URL shorteners: security and transparency. All links are thoroughly verified for viruses, malware, phishing, malicious content, session stealing, cross-site scripting attacks, etc. Any suspicious link gets flagged, and users are warned about it. Safe.mn is also the most transparent URL shortener service: all links generated by Safe.mn are publicly available, and updated regularly.


#10 User is offline   MysteryFCM Icon

  • Phishing Phanatic
  • PipPipPipPipPip
  • Group: Member - Experts
  • Posts: 533
  • Joined: 04-February 04

Awards Bar:

Users Awards

Posted 07 June 2009 - 04:37 PM

I'm a little curious as to how they check the target URL's and am skeptical of their claims.

I've just created one using their service, to a known malware site (listed in hpHosts), and their service didn't notify me of any problems, and created the short URL for me .... which likely means they're checking things manually (not a very good option for this kind of service)

#11 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 07 June 2009 - 04:50 PM

True which is why I have not recommend their short url service. It seems they are using 2 method: redirecting a redirection. I have not play with it.

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic


Disclaimer: While CalendarOfUpdates.com uses reasonable efforts to include accurate and up-to-date information, we make no warranties or representations as to the accuracy of the content and assume no liability or responsibility for any error or omission in the content. CalendarofUpdates.com does not represent or warrant that use of any content will not infringe rights of third parties. CalendarOfUpdates.com has no responsibility for actions of third parties or for content provided or posted by others.
All services are subject to the Terms of Service.
Except where otherwise stated, all content Copyright © 2003 - 2010 Dozleng, LLC