Shortened URLs Can Let Hackers Spy on You: Study

Advertisement
By Robin Sinha | Updated: 15 April 2016 19:14 IST

According to two researchers at Cornell Tech, while URL shortening tools may be useful, the short length makes it simple for hackers to brute force them, potentially exposing private information or even infecting cloud storage accounts with malware.

According to the researchers Martin Georgiev and Vitaly Shmatikov, it is possible to brute force shortened links from tech companies such as Google, Microsoft, and bit.ly that generate a Web address with only six seemingly random characters. The two researchers were able to use the trial and error method to discover Google Drive and Microsoft OneDrive files shared by short URLs. They also claim that out of their scanned accounts, around 7 percent of the OneDrive and Google Drive accounts were vulnerable in such way.

Advertisement

It was also possible to break inside a shortened Google Maps URLs that often contained routes between two private addresses, potentially leading to huge privacy issues. Some Maps links even contained details about users' medical facilities and places of worship.

The duo explained that Microsoft used Bit.ly service to generate short URLs for OneDrive files and folders. The researchers randomly generated 71 million OneDrive short URLs, out of which 24,000 were legitimate and let them access private files and folders. They even said that by opening the full length URL from the shortened ones, they could then tweak the Web address to access different folders by the same user.

Advertisement

"If someone wanted to inject a lot of malicious content into people's computers, it's a pretty interesting way of doing it," Wired quoted Shmatikov. "By scanning you can find these folders, you put whatever you want in them, and it gets automatically copied to people's hard drives."

For the search giant Google, the researchers said its Maps service like OneDrive used Bit.ly-generated shortened URLs that included shared locations and directions. They randomly generated 23 million shortened Google Maps URLs only to find that a massive almost 10 percent of them directly opened actual directions. The researchers said they could find directions requested by users to clinic for specific diseases, addiction treatment centres, abortion providers and more. Over 16,000 directions showed one end as the residence of the user.

Advertisement

They could even illustrate the level of threat caused by shortened Google Maps URL by pin pointing one of the users, identifying it as a young woman who shared directions to a Planned Parenthood facility, confirming her residence address, full name, and age as well.

Georgiev and Shmatikov started this research almost a year ago and notified Google about it in September last year. The company then responded by increasing the length of the URLs to 11 or 12 randomised characters, making them much harder to crack by brute force. The search giant even took measures to identify and block automated scanning of shortened URLs.

Advertisement

When the researchers approached Microsoft in May last year, the Redmond-based tech giant initially ignored the concerns but by last month removed the URL shortening feature from OneDrive. However, the researchers still say they could still successfully access all the identified vulnerable links. The detailed research study can be found here.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus N6x Design, Colour Options Teased Ahead of India Launch
  2. One UI 9 Beta Improves Samsung Galaxy S26 Ultra's Privacy Display Feature
  3. Tecno Camon 50 Ultra 5G Sale Begins in India Today
  4. Samsung Galaxy Z Fold 8 Ultra Could Cost More Than Expected, Listing Suggests
  5. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  6. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  7. QOO 16T Leak Hints at Flagship Chipset, and 2K Samsung Display
  1. Offline UPI Payments With NFC Support Could Launch in India Soon
  2. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  3. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  4. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  5. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  6. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  7. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  8. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  9. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  10. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.