
Shortened URLs are convenient: they’re a whole lot easier to handle than unwieldy strings that email messes up with line breaks when you cut and paste them.
But that same brevity also makes URLs from the likes of bit.ly, Google and Microsoft easier to crack, potentially exposing personal data to anyone who cares to look, security researchers have found.
Cornell Tech’s Martin Georgiev and Vitaly Shmatikov on Thursday published the results of an 18-month study that found the 5- or 6-character tokens added to domains such as 1drv.ms or goo.gl are so short, all possible URLs can be scanned by brute force by “anyone with a little patience and a few machines at her disposal.”
Those short URLs are, in effect, public, the researchers say.
The researchers didn’t scan all possible short URLs, though their analysis showed that a more powerful adversary could pull it off – say, with a botnet.
At any rate, they sampled enough to discover some alarmingly sensitive information that would be a boon to stalkers, along with files tied to folders with write-access that enable anyone, anywhere, to drop malicious code into your cloud storage.
The study focused on two cloud services that directly integrate URL shortening: Microsoft OneDrive (formerly known as SkyDrive) and Google Maps.
Out of the scanned OneDrive accounts, the pair claimed that 7% were vulnerable to “large-scale malware injection.”
Many of those OneDrive accounts held private documents, and many were unlocked. And because OneDrive synchronizes contents across a user’s OneDrive clients, the malware would automatically download onto all a user’s devices running the cloud storage.
Stalking came in on the Google Maps front. The researchers discovered
댓글 0