Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening Service
Zhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong, Yuan Zhang, Min Yang
摘要
—Dedicated URL shortening services (DUSSs) are designed to transform trusted long URLs into the shortened links. Since DUSSs are widely used in famous corporations to better serve their large number of users (especially mobile users), cyber criminals attempt to exploit DUSS to transform their malicious links and abuse the inherited implicit trust, which is defined as Misdirection Attack in this paper. However, little effort has been made to systematically understand such attacks. To fulfill the research gap, we present the first systematic study of the Misdirection Attack in abusing DUSS to demystify its attack surface, exploitable scope, and security impacts in the real world. Our study reveals that real-world DUSSs commonly rely on custom URL checks, yet they exhibit unreliable security assumptions regarding web domains and lack adherence to security standards. We design and implement a novel tool, Ditto 1 , for empirically studying vulnerable DUSSs from a mobile perspective. Our large-scale study reveals that a quarter of the DUSSs are susceptible to Misdirection Attack . More importantly, we find that DUSSs hold implicit trust from both their users and domain-based checkers, extending the consequences of the attack to stealthy phishing and code injection on users’ mobile phones. We have responsibly reported all of our findings to corporations of the affected DUSS and helped them fix their vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper22
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- FBS-Radar: Uncovering Fake Base Stations at Scale in the WildZhenhua Li, Weiwei Wang, Christo Wilson, Jian Chen 等NDSS 2017 · 被引用 92 次
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Are these Ads Safe: Detecting Hidden Attacks through the Mobile App-Web InterfacesVaibhav Rastogi, Rui Shao, Yan Chen, Xiang Pan 等NDSS 2016 · 被引用 81 次
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon 等S&P 2016 · 被引用 76 次
相关 Paper
- Measuring Identity Confusion with Uniform Resource LocatorsJoshua Reynolds, Deepak Kumar, Zane Ma, Rohan Subramanian 等CHI 2020 · 被引用 30 次
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu 等CCS 2026
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya 等CCS 2026
- URL Inspection Tasks: Helping Users Detect Phishing Links in EmailsDaniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik 等USENIX Security 2025
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 被引用 21 次
