Web Hack List

Collected research

Unauthorized TinyURL URL Enumeration Vulnerability

Securethoughts.com

Points out that TinyURL aliases are short, sequential-ish and unauthenticated, so anyone can walk the redirect endpoint and harvest the targets. A short Perl script generating random IDs and reading the Location header turned up credentials in query strings, corporate intranet URLs, live session identifiers and spam links.

Record

Document
Securethoughts.com
Published by
securethoughts.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of securethoughts.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .