Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

9/27/2012
11:16 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Are URL Shortening Services Unintentionally Promoting Malicious Websites?

Web of Trust found that URL shortening services are used to drive traffic to suspicious websites

Helsinki, Finland --- September 26, 2012 --- Web of Trust (WOT), a community-powered safe-surfing tool that helps web users find reliable websites, recently completed an analysis of nearly 1.7 billion shortened URL links and found that the URL shortening services are often used to drive traffic to suspicious websites.

WOT's research found that 8.7 percent of websites reached via the TinyURL service, and 5.0 percent of websites reached via Bit.ly, receive poor ratings for 'trustworthiness' and 'child protection' – as measured by WOT's millions of crowd-sourced reputation scores. Further analysis comparing the top level domain names (TLDs) that host these websites shows that the URL shortening services are often exploited to drive traffic to loosely-regulated countries where as much as 90% of the websites are suspicious. The top five most exploited domains are:

- .ac (Ascension Island) – 91% of websites are rated poorly

- .ms (Montserrat) – 65% of websites are rated poorly

- .pr (Puerto Rico) – 46% of websites are rated poorly

- .mu (Mauritius) – 36% of websites are rated poorly

- .tc (Turks and Caicos Islands) – 35% of websites are rated poorly

"Certainly the URL shortening services don't intend to point people to malicious websites, but perhaps they can do more to proactively protect their services from being exploited," said Markus Suomi, CEO of WOT. "These companies could automatically screen for potentially compromised website destinations, or at least inform their users when caution might be warranted before clicking on the link."

WOT's peer-authenticated reputation scores protect users around the world from exactly the things that traditional anti-virus software cannot: sites with questionable content, dubious online stores, unreliable vendors, and potential threats to child safely and privacy. The scores are based on WOT's community of millions of users and are used to help guide users toward reliable websites. Companies that currently license WOT's reputation data include Facebook, Mail.Ru Group, DuckDuckGo and many other global online properties.

Other Research Findings

Other findings from WOT's data analysis of websites reached via URL shortening services include:

1) The .com top-level domain (TLD) is the most popular by a wide margin, but as a percentage it hosts the fewest dangerous websites (only 2.5% of .com sites are rated poorly for 'trustworthiness' and 3.6% are rated poorly for 'child safety')

2) The three most common TLD alternatives to .com are corrupted by a surprisingly large percentage of poorly rates websites:

- .info – 10.7% of websites are rated poorly

- .net – 9.6% of websites are rated poorly

- .biz – 9.5% of websites are rated poorly

WOT's analysis was based on data collected since the very inception of Bit.ly in 2008 and TinyURL in 2002, through to the end of December 2011.

How to Install WOT

Web users can start using WOT by downloading the free WOT add-on to their browsers (available for Internet Explorer, Firefox, Google Chrome, Safari and Opera).

About WOT Services

Web of Trust (WOT) is a community-powered browser add-on that helps web users find reliable websites. WOT uses an intuitive traffic-light rating system to help web users stay safe when they search, surf and shop online. Website ratings are crowd-sourced from a fast growing worldwide community of WOT users who have rated the reputation of 38 million websites based on their experiences in terms of trustworthiness, vendor reliability, privacy and child safety. Community ratings are augmented with information from selected technical data services. The WOT add-on works with Firefox, Google Chrome, Internet Explorer, Opera and Safari and is a free download from www.mywot.com.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
The State of Email Security and Protection
Mike Flouton, Vice President of Email Security at Barracuda Networks,  11/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprise
Assessing Cybersecurity Risk in Today's Enterprise
Security leaders are struggling to understand their organizations risk exposure. While many are confident in their security strategies and processes, theyre also more concerned than ever about getting breached. Download this report today and get insights on how today's enterprises assess and perceive the risks they face in 2019!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18881
PUBLISHED: 2019-11-12
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
CVE-2019-18882
PUBLISHED: 2019-11-12
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
CVE-2019-18873
PUBLISHED: 2019-11-12
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the pa...
CVE-2019-18874
PUBLISHED: 2019-11-12
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
CVE-2019-18862
PUBLISHED: 2019-11-11
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.