LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services
Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal, Stefano Calzavara, Ben Stock
Abstract
URL scanning services are widely used in security workflows to detect malicious websites and protect users from online threats. However, their common practice of publicly indexing scanned URLs may unintentionally expose sensitive user information through URL-embedded access credentials. Although isolated accounts of such privacy incidents exist, a systematic assessment of their prevalence is still lacking.
We present LEAKYLINKS, an automated analysis pipeline that combines URL filtering with LLM-driven semantic classification to identify URLs exposing Sensitive Personal Information (SPI). Using LEAKYLINKS, we analyze URLs collected from public feeds of six prominent URL scanning services over a period of three weeks. With the framework, we visited 332k URLs, identifying over 4k URLs which leak SPI with a precision of 97%.
To further assess the extent to which published URLs are actively accessed by third parties, we deploy honeypages and submit their links to the selected URL scanning services. Our measurements confirm that external entities access URLs submitted to these scanners, often from potentially suspicious IPs exhibiting behavior commonly associated with reconnaissance or opportunistic probing.
Taken together, these findings indicate that URL scanning services represent a valuable target for web adversaries and may already be subject to active exploitation in the wild.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7e12b9c1-d3cd-45e6-b2dc-16fe4649896bBuilds on7
- Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public GatewaysBradley Reaves, Nolen Scaife, Dave Tian, Logan Blue et al.S&P 2016 · 68 citations
- LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scaleJonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers et al.USENIX Security 2024 · 5 citations
- The Security Lottery: Measuring Client-Side Web Security InconsistenciesSebastian Roth, Stefano Calzavara, Moritz Wilhelm, Alvise Rabitti et al.USENIX Security 2022
- Evaluating LLM-based Personal Information Extraction and CountermeasuresYupei Liu, Yuqi Jia, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2025
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
Related papers
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya et al.CCS 2026
- PIIxel Leaks: Passive Identification of Personally Identifiable Information Leakage through Meta PixelPaschalis Bekos, Panagiotis Papadopoulos, Nicolas Kourtellis, Michalis PolychronakisCCS 2025
- Keys on Doormats: Exposed API Credentials on the WebNurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir DurumericCCS 2026 · 2 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM ServicesZhihuang Liu, Ling Hu, Yonghao Tang, Tongqing Zhou et al.WWW 2026
