Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

URL shortening service has links hacked

Cli.gs broken by attacker.

Article comments

The Cli.gs URL-shortening service yesterday reported that an attacker managed break in via a software security hole and take over 2.2 million URL links.

The Cli.gs service works like TinyURL to convert a long URL into a short link that is easier to use in e-mails, IMs and other messages. And lucky for Cli.gs users, this attack doesn't appear to have been intended to infect hapless surfers.

According to security company Sophos, the hacked links took visitors to an Orange County Register blog posting on Twitter hashtags. Anti-virus maker Kaspersky confirmed there was "No malicious code has been found on that particular page," and suggests the hacker meant to show the site was vulnerable to attack but not harm PCs.

According to the Cli.gs post, cligs editing is currently disabled to prevent further hijacks using the same security hole, and the site is in the process of restoring links from a backup. However, the latest backup is from May, so links created since then may have been lost, per the post.

Cli.gs, TinyURL and URL-shortening services in general are pulling in plenty of hacker attention. While this particular break-in doesn't appear to be malicious, crooks have used such services to obfuscate phishing links and other attacks.

To foil these dirty tricks, Firefox users can use the straightforward LongURL add-on, which will display the full URL for links from any shortening service in a pop-up. Also, the TinyURL service allows setting a preview option (with a cookie) to see the URL before visiting it.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *