Wednesday, November 24, 2010

Security Risk Behind Shortened URL's

Shortening a URL is easy and we most of times use site such as TinyURL, bit.ly, is.gd, and more to shorten our bulky links.
But When we see such URL's we cannot predict by seeing them where these URL's will land us or may be used to hide identity of malicious  sites.

Take example of bit.ly
Look at this URL
http://bit.ly/d3DyI0

You cannot say where this will take you by simple looking at it.But To see where it will land you at just add a + sign at the end of the url and paste it address bar and you will see all the information.This URL simple take to my own blog.

http://bit.ly/d3DyI0+



TinyURL has a similar option. But instead of adding a plus sign at the end of a link, you prepend the word preview.
Example 
http://tinyurl.com/367pwvr


Now Add preview before the tinyurl as 
http://preview.tinyurl.com/367pwvr


This will show you the actual URL behind the tiny URL.



If you're checking lots of links, it can be clunky to manually copy, paste, and edit URLs. Several sites offer automated scripts to make things a bit easier. For example, when you encounter a suspicious short URL, you can click to Longurl, ExpandMyURL.com, orLong URL Please.com.

Paste the suspect short URL into these sites' dialog boxes, and they'll show you the full, expanded link.

No comments: