Sunday, August 10, 2025
  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Computing

Researchers Crack Shortened URLs; Makes It Easy To Spy On People

by Farhan
April 18, 2016
213
SHARES
Share on FacebookShare on Twitter

A group of researchers from Cornell University have discovered a way of reverse engineering shortened URLs to perform a multitude of actions; including spreading malware and stealing personal information. All this on a system that was designed to conceal information to prevent this from happening.

The researchers had original tested their theory of simply using brute force against shortened URLs to see what they could access. Essentially, they simply changed the six-characters at the end of shortened URLs like Bit.ly until they found something they could modify. In this case, the vulnerability lay with Microsoft’s OneDrive.

OneDrive and Microsoft Office

About seven percent of the tested shortened URLs resulted in a OneDrive file that could be edited in some way. It doesn’t sound like much, but the weakness could make it easy for cybercriminals to inject malware into private documents without the knowledge of the owner.

The researchers also applied their method to Google Maps and turned up location and navigation data of users. The hit chance was slightly higher for Google Maps related attempts, with 10-percent of the 230 million tested URLs turning up visible results like “clinics for specific diseases (including cancer and mental illnesses), addiction treatment centers, abortion providers, correctional and juvenile detention facilities, payday and car-title lenders, [and] gentlemen’s clubs.”

More often than not, these locations would also reveal a residential address. The researchers claim that the mapping information could be used to discover other information about an individual.

Lane Guidance For Google Maps

The problem is not just limited to Google Maps, but also extends to other mapping services like Mapquest, Bing Maps, and Yahoo! Maps.

At the moment, both Google and Microsoft have taken steps to mitigate the problem with shortened URLs. Google has increased the number of randomised characters used from six to twelve; while Microsoft has simply disabled the option of sharing files through shortened URLs.

That being said, the study only shows the danger in using URL shorteners to share private links. The researchers warn that the public needs to be more aware about what is involved with shortening URLs; and that anonymity is not really a defence on the internet.

[Source: Cornell Research Paper; via: Wired]

Filed Under BitlyURL Shortener
Updated 12:30 pm, Mon, 18 April 16
https://lowy.at/b56Kj
Share85Tweet53SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    News

    You Can Now Apply To Switch To TNB ToU Billing Via myTNB Portal

  2. 2
    Mobile Phones

    Redmi 15 5G Now Official And Available For RM729 In Malaysia

  3. 3
    Accessories

    CUKTECH Launches Power Bank, Mini Fan; Priced From RM47

  4. 4
    Rumours & Leaks

    NVIDIA Reportedly Planning “Aggressive” Price Cuts For RTX 50 Series GPUs

  5. 5
    Mobile Phones

    Xiaomi Malaysia Teases Redmi 15 5G With 7,000 mAh Battery

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.