Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening Service
Zhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong, Yuan Zhang, Min Yang
Abstract
—Dedicated URL shortening services (DUSSs) are designed to transform trusted long URLs into the shortened links. Since DUSSs are widely used in famous corporations to better serve their large number of users (especially mobile users), cyber criminals attempt to exploit DUSS to transform their malicious links and abuse the inherited implicit trust, which is defined as Misdirection Attack in this paper. However, little effort has been made to systematically understand such attacks. To fulfill the research gap, we present the first systematic study of the Misdirection Attack in abusing DUSS to demystify its attack surface, exploitable scope, and security impacts in the real world. Our study reveals that real-world DUSSs commonly rely on custom URL checks, yet they exhibit unreliable security assumptions regarding web domains and lack adherence to security standards. We design and implement a novel tool, Ditto 1 , for empirically studying vulnerable DUSSs from a mobile perspective. Our large-scale study reveals that a quarter of the DUSSs are susceptible to Misdirection Attack . More importantly, we find that DUSSs hold implicit trust from both their users and domain-based checkers, extending the consequences of the attack to stealthy phishing and code injection on users’ mobile phones. We have responsibly reported all of our findings to corporations of the affected DUSS and helped them fix their vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1b10b5c0-d9fb-4c02-9e64-45ef9846dde0Cited by top-tier papers1
Ask how each one uses itBuilds on22
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- FBS-Radar: Uncovering Fake Base Stations at Scale in the WildZhenhua Li, Weiwei Wang, Christo Wilson, Jian Chen et al.NDSS 2017 · 92 citations
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 91 citations
- Are these Ads Safe: Detecting Hidden Attacks through the Mobile App-Web InterfacesVaibhav Rastogi, Rui Shao, Yan Chen, Xiang Pan et al.NDSS 2016 · 81 citations
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon et al.S&P 2016 · 76 citations
Related papers
- Measuring Identity Confusion with Uniform Resource LocatorsJoshua Reynolds, Deepak Kumar, Zane Ma, Rohan Subramanian et al.CHI 2020 · 30 citations
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu et al.CCS 2026
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya et al.CCS 2026
- URL Inspection Tasks: Helping Users Detect Phishing Links in EmailsDaniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik et al.USENIX Security 2025
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
