Shortened URLs Can Let Hackers Spy on You: Study

Advertisement
By Robin Sinha | Updated: 15 April 2016 19:14 IST
Shortened URLs Can Let Hackers Spy on You: Study

According to two researchers at Cornell Tech, while URL shortening tools may be useful, the short length makes it simple for hackers to brute force them, potentially exposing private information or even infecting cloud storage accounts with malware.

According to the researchers Martin Georgiev and Vitaly Shmatikov, it is possible to brute force shortened links from tech companies such as Google, Microsoft, and bit.ly that generate a Web address with only six seemingly random characters. The two researchers were able to use the trial and error method to discover Google Drive and Microsoft OneDrive files shared by short URLs. They also claim that out of their scanned accounts, around 7 percent of the OneDrive and Google Drive accounts were vulnerable in such way.

It was also possible to break inside a shortened Google Maps URLs that often contained routes between two private addresses, potentially leading to huge privacy issues. Some Maps links even contained details about users' medical facilities and places of worship.

The duo explained that Microsoft used Bit.ly service to generate short URLs for OneDrive files and folders. The researchers randomly generated 71 million OneDrive short URLs, out of which 24,000 were legitimate and let them access private files and folders. They even said that by opening the full length URL from the shortened ones, they could then tweak the Web address to access different folders by the same user.

Advertisement

"If someone wanted to inject a lot of malicious content into people's computers, it's a pretty interesting way of doing it," Wired quoted Shmatikov. "By scanning you can find these folders, you put whatever you want in them, and it gets automatically copied to people's hard drives."

For the search giant Google, the researchers said its Maps service like OneDrive used Bit.ly-generated shortened URLs that included shared locations and directions. They randomly generated 23 million shortened Google Maps URLs only to find that a massive almost 10 percent of them directly opened actual directions. The researchers said they could find directions requested by users to clinic for specific diseases, addiction treatment centres, abortion providers and more. Over 16,000 directions showed one end as the residence of the user.

Advertisement

They could even illustrate the level of threat caused by shortened Google Maps URL by pin pointing one of the users, identifying it as a young woman who shared directions to a Planned Parenthood facility, confirming her residence address, full name, and age as well.

Georgiev and Shmatikov started this research almost a year ago and notified Google about it in September last year. The company then responded by increasing the length of the URLs to 11 or 12 randomised characters, making them much harder to crack by brute force. The search giant even took measures to identify and block automated scanning of shortened URLs.

Advertisement

When the researchers approached Microsoft in May last year, the Redmond-based tech giant initially ignored the concerns but by last month removed the URL shortening feature from OneDrive. However, the researchers still say they could still successfully access all the identified vulnerable links. The detailed research study can be found here.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X200 FE Compact Smartphone Launched With 6,500mAh Battery
  2. Kubera OTT Release Reportedly Revealed: Where to Watch Dhanush Starrer Movie Online?
  3. Oppo K13x 5G With 6,000mAh Battery Launched in India: See Price
  4. Xiaomi Mix Flip 2, Redmi K80 Ultra Set to Launch on This Date
  1. ‘Ghost’ Plume Found Beneath Oman May Explain India’s Ancient Tectonic Shift
  2. Blue Origin’s Crewed Suborbital Launch Delayed Again Due to Weather Conditions
  3. Green Rooftops Could Help Cities Like Shanghai Filter Out Tons of Microplastics from Rainwater
  4. SpaceX to Launch Over 150 Memorial DNA Capsules into Orbit on Celestis’ Perseverance Flight
  5. Rubin Observatory to Unveil First Cosmic Images with World’s Largest Digital Camera
  6. The Gilded Age OTT Release: Where to Watch This HBO Original Series
  7. Cleaner (2025) OTT Release Date: When and Where to Watch it Online?
  8. Yugi Now Available for Streaming on Aha Tamil: Everything You Need to Know
  9. Samsung Exynos 2500 SoC With Up to 15 Percent Improved CPU Performance, Xclipse 950 GPU Launched
  10. Vivo X200 FE With 6,500mAh Battery, MediaTek Dimensity 9300+ SoC Launched: Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.