URL Shortening
Shortened URLs offers several benefits by playing a vital role in digital marketing by transforing lengthy URL into short and simple URL which can be shared on social media, blogs, emails and more.
It is a technique that will redirect your short URL to specific website of your choice.
And searching random shortened URLs could yield all sorts of secret documents. Plus, many of them can be edited, and can be infected with malware.
Security implication
Most URL shortening domains are trusted by firewalls, Web filters or spam blocking tools , and other security analysis solutions fail to detect the real URL’s destination. This makes it difficult to identify links that lead to malicious destinations.
Possible Control
Below image depicts the technique used by shortened URLs
Security implication
Most URL shortening domains are trusted by firewalls, Web filters or spam blocking tools , and other security analysis solutions fail to detect the real URL’s destination. This makes it difficult to identify links that lead to malicious destinations.
Risk Statement
Current State or Condition
|
Consequence
|
Since the short URL are frequently used with social networks
like Twitter, Facebook, telegram,
|
since there is an inherent trust that the link
will be legitimate, there is high
probability that users are going to click without taking into account the
security risk they might be exposed to.
|
Since the user cannot see the original url where the browser
will be redirected to.
|
The users may be tricked into visiting malicious web sites and
allowing a successful url redirection attack compromising the user system.
|
CWE-601: URL
Redirection to Untrusted Site ('Open Redirect')
Possible Control
- Configure your appliance to perform URL filtering on shortened URLs, and retrieve the actual URL from the shortened URL and inspect the web content.
- Enable detecting control by enabling recording of short url along with the expanded original url and generate appropriate alerst for further security incident analysis and management.
- Conduct reputation analysis by Configuring your content filters with appropriate URL Reputation rules and actions to take on malicious URLs.
How to validate short URL.
There are a number of ways you can reveal the full URL behind a shortened URL:
There are a number of ways you can reveal the full URL behind a shortened URL:
- Use the shortening service preview feature. Type the shortened URL in the address bar of your web browser and add the characters described below to see a preview of the full URL:
- tinyurl.com. Between the "http://" and the "tinyurl," type preview. Example: http://preview.tinyurl.com/zn7xnzu
- bit.ly. At the end of the URL, type a + Example: http://bit.ly/2lgPesi+
- goo.gl. At the end of the URL, type a + Example: https://goo.gl/vLfoaW+
2. Use a URL checker. These are just a few of the sites that let you enter a short URL and then see the full URL:
References
- https://www.scitepress.org/Papers/2011/35798/35798.pdf
- https://www.sans.org/security-awareness-training/blog/secure-options-url-shortening
- https://blog.trendmicro.com/are-shortened-urls-safe/
- https://dzone.com/articles/how-a-url-shortening-application-works
- https://cwe.mitre.org/data/definitions/601.html
- https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118775-technote-esa-00.html
- https://www.forcepoint.com/blog/insights/bitly-leverages-websense-protect-users-spam-phishing-and-malware
Comments
Post a Comment