百度空间 | 百度首页 
 
查看文章
 
Wholesale Redirects to Malware Averted, For Now(缩短网址服务安全性有待提高)
2009-06-18 23:37

URL redirection services like TinyURL have grown from almost nothing in recent years, due entirely to the success of Twitter and its 140-character limit. For most users, they represent a welcome convenience as they make their tweets, status messages, and other such space-limited posts throughout the day.

Unfortunately, cybercriminals have used such services as part of various schemes before. Earlier this week, in fact, it’s safe to say the Internet dodged a big bullet.

The database of Cligs, the #4 URL redirection service used on Twitter, was compromised sometime on Sunday night/Monday morning. According to the official Cligs blog, approximately 2.2 million redirects were edited to go to a post talking about Twitter hash tags at a blog maintained by the Orange County Register. It’s unclear who did it and why, although it might well be a case of it being done because it could be done.

While the attack caused little long-term damage, it could have been indescribably worse. Had it happen to a bigger redirection service like Bitly or TinyURL, the numbers of affected users would have been far greater. In addition, the links didn’t go anywhere malicious. It would have been just as easy for the links to go to malware – and it wouldn’t have been very hard to do so in a way that would be invisible to most users.

This could have been a far bigger problem, but thankfully it wasn’t. What it is, however, is a warning about the dangers of URL redirection. There’s not much consumers can do on their own, but providers should double-check their own security measures.



Read more: http://blog.trendmicro.com/wholesale-redirects-to-malware-averted-for-now/

——————————————————————————

       网址重定向服务,比如最近几年TinyURL,bit.ly 爆发式的增长,由于Twitter的成功,和140个字的限制,使得缩短网址服务也顺应着流行起来了。对于大多数用户来说,他们给千千万万的Twitter们带来方便。
不幸的是,网络犯罪分子利用这种服务的一部分,各种计划之前。本星期早些时候,事实上,可以肯定地说互联网躲过了大子弹。

     上个星期天晚上到星期一上午,
Cligs的网址重定向服务数据库 被篡改并在Twitter上被广泛使用。根据官方Cligs博客,大约有二百万个链接被重定向到恶意网站。目前还不清楚谁做的,和为什么要这样做,但它很可能是病毒集团所为。

虽然这次袭击没有造成长期的损害,但往后它可能会发生更重大攻击。如果它发生在一个更大的短址服务服务商像Bitly或TinyURL 上面,数量的受影响的用户将大得多。此外,不需要太多的攻击行为。只是把短链接简单的链接到恶意软件-它本来是很难这样做是比较难损害大部分的用户的,但也会对部分用户造成困扰。

     看来给用户一个安全的短链接是这些短址供应商们应仔细琢磨的地方了。目前国外提供了安全性检测的有
nn.nf,minmu.net 等的厂商,而国内同样也有 缩吧(s8.hk) 等提供安全性检测的短址服务商。


类别:新闻消息 | 添加到搜藏 | 浏览() | 评论 (2)
 
最近读者:
 
网友评论:
1
2009-06-23 17:59 | 回复
这个风险很大,TinyURL的短址连接,很多被QQ屏蔽了,如果饭否、滔滔们在中国发达了,估计利用这个攻击的东西就会此起彼伏。
 
2
2009-06-30 12:53 | 回复
缩短了,直接看不出是哪里。。。
 
发表评论:
姓 名:
网址或邮箱: (选填)
内 容:
验证码: 请点击后输入四位验证码,字母不区分大小写
      

     

©2009 Baidu