Home TinyURL Being Used to Bypass Safe Browsing Filters in Firefox, Chrome

TinyURL Being Used to Bypass Safe Browsing Filters in Firefox, Chrome

TinyURL, one of the most popular URL-shortening services (although not our favorite) is now being used by cybercriminals to redirect web surfers to pages that contain viruses, trojans, and other sorts of malware. According to Finjan’s Malicious Code Research Center, these criminals are using the service to avoid having their web sites flagged by the Safe Browsing mechanisms built in to modern web browsers like Mozilla Firefox and Google Chrome.

Both web browsers employ Google Safe Browsing, a feature which warns users about phishing sites and other malware. Yet bypassing this filter within your browser is easy to do, apparently. All that’s necessary is for a cybercriminal to create a TinyURL that hides the original, malicious URL. Then, instead of getting the warning message “Reported Attack Site!”, unsuspecting web surfers will be sent directly to the dangerous web page when clicking the link.

In tests, the reason that the TinyURLs were able to be used in this way is because the pages they masked were not at the domain level, but were rather sub-pages of a domain marked as “safe.” This actually points to a weakness in the Safe Browsing feature and not really a security risk in the TinyURL service in and of itself. Because Safe Browsing only ranks sites at the domain level, infected sub-pages will always be ranked as “non-malicious” as long as the domain is categorized as “safe.”

TinyURL isn’t the only service being abused in this way. Other URL-shortening services mentioned in the article include bit.ly, w3t.org and is.gd. However, during their research, the firm also found bit.ly being used by the same cybercriminals. Both TinyURL and bit.ly were notified and the malicious links were removed.

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the tech industry for major developments, new product launches, AI breakthroughs, video game releases and other newsworthy events. Editors assign relevant stories to staff writers or freelance contributors with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Get the biggest tech headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Tech News

    Explore the latest in tech with our Tech News. We cut through the noise for concise, relevant updates, keeping you informed about the rapidly evolving tech landscape with curated content that separates signal from noise.

    In-Depth Tech Stories

    Explore tech impact in In-Depth Stories. Narrative data journalism offers comprehensive analyses, revealing stories behind data. Understand industry trends for a deeper perspective on tech's intricate relationships with society.

    Expert Reviews

    Empower decisions with Expert Reviews, merging industry expertise and insightful analysis. Delve into tech intricacies, get the best deals, and stay ahead with our trustworthy guide to navigating the ever-changing tech market.