[HACK] URL Shortners


SUBMITTED BY: m3535wewe

DATE: Sept. 28, 2015, 9 a.m.

UPDATED: Sept. 28, 2015, 9:13 a.m.

FORMAT: Text only

SIZE: 739 Bytes

HITS: 1084

  1. Abusing URL Shortners to discover sensitive resources or assets
  2. The specific method describes how its possible to salvage a bunch of potentially sensitive/or confidential URLs via the Bit.ly SaaS used by a large number of corporations (and those who offer bounties).
  3. X corporation uses the URL shortner domain http://xyz.com. We can check whether or not it's a Bitly URL shortner service by visiting http://xyz.com/debug.
  4. We can now run a directory/file bruteforce on this URL shortner service in order to find links that have been generated by staff at said company through the shortner.
  5. For example, by using the dirs3arch tool we can brute this Bitly endpoint in order to find URLs that could potentially be sensitive.

comments powered by Disqus