Thursday, December 11, 2025
  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Computing

Researchers Crack Shortened URLs; Makes It Easy To Spy On People

by Farhan
April 18, 2016
Share on FacebookShare on Twitter

A group of researchers from Cornell University have discovered a way of reverse engineering shortened URLs to perform a multitude of actions; including spreading malware and stealing personal information. All this on a system that was designed to conceal information to prevent this from happening.

The researchers had original tested their theory of simply using brute force against shortened URLs to see what they could access. Essentially, they simply changed the six-characters at the end of shortened URLs like Bit.ly until they found something they could modify. In this case, the vulnerability lay with Microsoft’s OneDrive.

OneDrive and Microsoft Office

About seven percent of the tested shortened URLs resulted in a OneDrive file that could be edited in some way. It doesn’t sound like much, but the weakness could make it easy for cybercriminals to inject malware into private documents without the knowledge of the owner.

The researchers also applied their method to Google Maps and turned up location and navigation data of users. The hit chance was slightly higher for Google Maps related attempts, with 10-percent of the 230 million tested URLs turning up visible results like “clinics for specific diseases (including cancer and mental illnesses), addiction treatment centers, abortion providers, correctional and juvenile detention facilities, payday and car-title lenders, [and] gentlemen’s clubs.”

More often than not, these locations would also reveal a residential address. The researchers claim that the mapping information could be used to discover other information about an individual.

Lane Guidance For Google Maps

The problem is not just limited to Google Maps, but also extends to other mapping services like Mapquest, Bing Maps, and Yahoo! Maps.

At the moment, both Google and Microsoft have taken steps to mitigate the problem with shortened URLs. Google has increased the number of randomised characters used from six to twelve; while Microsoft has simply disabled the option of sharing files through shortened URLs.

That being said, the study only shows the danger in using URL shorteners to share private links. The researchers warn that the public needs to be more aware about what is involved with shortening URLs; and that anonymity is not really a defence on the internet.

[Source: Cornell Research Paper; via: Wired]

Filed Under BitlyURL Shortener
Updated 12:30 pm, Mon, 18 April 16
https://lowy.at/b56Kj
Share1Tweet1SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Mobile Phones

    Specs Of Redmi Note 15 Series’ Global Variant Appear Online

  2. 2
    News

    Next-Gen MyKad To Be Implemented In Phases

  3. 3
    Automotive

    Perodua Teases New Model Which Resembles The Nexis

  4. 4
    Transportation

    LRT3 Opening Delayed Again Amid Testing Setbacks

  5. 5
    Transportation

    AirBorneo’s Jet Operations To Start Next July; Singapore As One Of First Destinations

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.