Web Hack List

Other nomination

Unauthorized TinyURL URL Enumeration Vulnerability

Points out that TinyURL aliases are short, sequential-ish and unauthenticated, so anyone can walk the redirect endpoint and harvest the targets. A short Perl script generating random IDs and reading the Location header turned up credentials in query strings, corporate intranet URLs, live session identifiers and spam links.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.