<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.13530-</id>
  <updated>2011-08-16T17:51:36Z</updated>
  <title>Comments for TinyURL Being Used to Bypass Safe Browsing Filters in Firefox, Chrome</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=13530" title="TinyURL Being Used to Bypass Safe Browsing Filters in Firefox, Chrome" />
    <published>2009-01-26T13:49:37Z</published>
    <updated>2009-01-26T14:00:00Z</updated>
    <title>TinyURL Being Used to Bypass Safe Browsing Filters in Firefox, Chrome</title>
    <summary>TinyURL, one of the most popular URL-shortening services (although not our favorite) is now being used by cybercriminals to redirect web surfers to pages that contain viruses, trojans, and other sorts of malware. According to Finjan&apos;s Malicious Code Research Center, these criminals are using the service to avoid having their web sites flagged by the...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="NYT" />
    
    <category term="Search" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/attack_icon.png"><a href="http://tinyurl.com">TinyURL</a>, one of the most popular URL-shortening services (although not <a href="http://www.readwriteweb.com/archives/bitly_alternative_to_tinyurl.php">our favorite</a>) is now being used by cybercriminals to redirect web surfers to pages that contain viruses, trojans, and other sorts of malware. According to <a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2153">Finjan's Malicious Code Research Center</a>, these criminals are using the service to avoid having their web sites flagged by the Safe Browsing mechanisms built in to modern web browsers like <a href="http://getfirefox.com/">Mozilla Firefox</a> and <a href="http://www.google.com/chrome/">Google Chrome</a>. </p>]]>
      <![CDATA[

<p>Both web browsers employ <a href="http://www.google.com/tools/firefox/safebrowsing/">Google Safe Browsing</a>, a feature which warns users about phishing sites and other malware. Yet bypassing this filter within your browser is easy to do, apparently. All that's necessary is for a cybercriminal to create a TinyURL that hides the original, malicious URL. Then, instead of getting the warning message "Reported Attack Site!", unsuspecting web surfers will be sent directly to the dangerous web page when clicking the link. </p>

<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="EvasiveURL1.JPG" src="http://www.readwriteweb.com/images/EvasiveURL1.JPG" width="450" height="218" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /></span>

<p>In tests, the reason that the TinyURLs were able to be used in this way is because the pages they masked were not at the domain level, but were rather sub-pages of a domain marked as "safe." This actually points to a weakness in the Safe Browsing feature and not really a security risk in the TinyURL service in and of itself. Because Safe Browsing only ranks sites at the domain level, infected sub-pages will always be ranked as "non-malicious" as long as the domain is categorized as "safe." </p>

<p>TinyURL isn't the only service being abused in this way. Other URL-shortening services mentioned in the article include <a href="http://bit.ly/">bit.ly</a>, <a href="http://w3t.org/">w3t.org</a> and <a href="http://is.gd/">is.gd</a>. However, during their research, the firm also found bit.ly being used by the same cybercriminals. Both TinyURL and bit.ly were notified and the malicious links were removed. </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:306576</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c306576" />
    <title>Comment from altın çilek on 2011-03-01</title>
    <author>
        <name>altın çilek</name>
        <uri>http://www.altincilek.tk</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.altincilek.tk">
        <![CDATA[<p>URL shortners never appealed to me much. Just check this security site to stay up to date.</p>]]>
    </content>
    <published>2011-03-01T10:34:00Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124782</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124782" />
    <title>Comment from Steve on 2009-01-28</title>
    <author>
        <name>Steve</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I think some of these issues have already been solved.  Regardless, the fact malware detectors etc. are only at the domain level is not too comforting.  URL shortners never appealed to me much.  Just check <a href="http://www.justaskgemalto.com/" rel="nofollow">this security site</a> to stay up to date.</p>]]>
    </content>
    <published>2009-01-29T05:44:39Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124474</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124474" />
    <title>Comment from Mike Beltzner on 2009-01-26</title>
    <author>
        <name>Mike Beltzner</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>(It's possible that the research was run on Firefox 2, which is no longer supported and has a different SafeBrowsing implementation.)</p>]]>
    </content>
    <published>2009-01-27T01:05:21Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124469</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124469" />
    <title>Comment from Mike Beltzner on 2009-01-26</title>
    <author>
        <name>Mike Beltzner</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>The research is flawed. The SafeBrowsing service checks the full URL against the database, and checks the URL of the resource being loaded, not the reference. This way any redirects - caused by server side redirects, shorteners like TinyURL or otherwise - cannot defeat the service.</p>

<p>See <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=475436" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=475436</a> which was opened based on this article and quickly resolved as invalid.</p>]]>
    </content>
    <published>2009-01-26T23:57:11Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124463</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124463" />
    <title>Comment from John Adams on 2009-01-26</title>
    <author>
        <name>John Adams</name>
        <uri>http://www.retina.net/etch</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.retina.net/etch">
        <![CDATA[<p>I am shocked to hear that bit.ly is vulnerable to this as well -- they process URLs through google's malware service and shouldn't have this issue.</p>]]>
    </content>
    <published>2009-01-26T22:08:47Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124440</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124440" />
    <title>Comment from Jean-Michel Decombe on 2009-01-26</title>
    <author>
        <name>Jean-Michel Decombe</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Haha, that is great. Another blow to the face of URL shorteners, which are one of the worst ideas ever, from a technical standpoint.</p>]]>
    </content>
    <published>2009-01-26T17:25:49Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124428</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124428" />
    <title>Comment from Łukasz on 2009-01-26</title>
    <author>
        <name>Łukasz</name>
        <uri>http://media2.pl/technologie/45576-microsoft-wie,-gdzie-sa-pieniadze.html</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://media2.pl/technologie/45576-microsoft-wie,-gdzie-sa-pieniadze.html">
        <![CDATA[<p>I want chrome on Linux...</p>]]>
    </content>
    <published>2009-01-26T16:16:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124420</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124420" />
    <title>Comment from MKR on 2009-01-26</title>
    <author>
        <name>MKR</name>
        <uri>http://www.mkronline.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.mkronline.com/">
        <![CDATA[<p>The simplest solution I can think of is to have the browser warn the user when a page tries to redirect to another domain.</p>]]>
    </content>
    <published>2009-01-26T15:34:28Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124417</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124417" />
    <title>Comment from Sarah Perez on 2009-01-26</title>
    <author>
        <name>Sarah Perez</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@Michael As in Panera Bread? Wow, I wasn't aware of that. (Although I tend to hang out at Starbucks). Potential solutions are needed indeed!</p>]]>
    </content>
    <published>2009-01-26T15:14:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124416</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124416" />
    <title>Comment from Michael Russell - @planetrussell on 2009-01-26</title>
    <author>
        <name>Michael Russell - @planetrussell</name>
        <uri>http://www.planetrussell.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.planetrussell.net">
        <![CDATA[<p>Cafe Panera, a popular North-American eatery known for its fresh baked goods (and free WiFi access) blocks TinyURL.com apparently for this exact reason. </p>

<p>Curiously, other URL shortening services appear to work under certain circumstances, however. This has serious implications on how 'net access is used in establishments like Panera. If you can't retweet using a shortening service, you  probably won't use Twitter -- or any of several other services at all. And, if you're limited in what you can do at such establishments, your incentive to patronize them is diminished. Potential solutions?</p>]]>
    </content>
    <published>2009-01-26T15:08:29Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124415</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124415" />
    <title>Comment from David Bloom on 2009-01-26</title>
    <author>
        <name>David Bloom</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It seems to work just fine for me in Opera and Firefox.</p>

<p>Here's a tinyurl to a known phishing site to test your browser: <a href="http://tinyurl.com/bvkd85" rel="nofollow">http://tinyurl.com/bvkd85</a></p>]]>
    </content>
    <published>2009-01-26T14:53:23Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13530-comment:124414</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13530" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/tinyurl_being_used_to_bypass_safe_browsing_filters.php#c124414" />
    <title>Comment from MKR on 2009-01-26</title>
    <author>
        <name>MKR</name>
        <uri>http://www.mkronline.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.mkronline.com/">
        <![CDATA[<p><a href="http://tinyurl.com/preview.php" rel="nofollow">http://tinyurl.com/preview.php</a></p>

<p>:)</p>]]>
    </content>
    <published>2009-01-26T14:34:37Z</published>
  </entry>

</feed>
