Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Spot the Tiny Phishing Trick

By Erik Larkin, PC World
March 13, 2009 03:40 PM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

The TinyURL service allows you to enter a long URL, such as one for a particular Google Maps location, and convert it into a short, easy-to-type or e-mail link. Good for sending links - or as Trend Micro reports, for hiding a malicious Web site URL in a phishing e-mail.

Slideshow: Spammers in the slammer
Slideshow: Famous last words about spam

Trend says the dirty trick, which it first reported on in February, is becoming more popular and spreading into multiple languages. The ruse is intended to make it more difficult for the wary to immediately peg a link as suspicious when they mouseover a link to see where it actually goes.

Of course, you'd probably be just as suspicious if you receive an e-mail that purports to be from your bank but uses a TinyURL, but Trend also writes that the technique is being used for IM-based phishing with messages that pretend to come from a friend.

If you suspect that a TinyURL link you've received might hide a malicious URL, you can check it out without clicking the link. First copy the link to the clipboard and paste it into your browser's address bar, or type it in directly. Then type 'preview' before the address, so that http://tinyurl.com/g0hz would become http://preview.tinyurl.com/g0hz, for example.

Then hit enter to bring up a preview page, and you'll see the full URL used for the TinyURL link without actually bringing up the linked-to page. If you want to see if that link has been reported as a phishing site, or if you want to report it as such yourself, cut and paste the (real) link and enter it on http://www.phishtank.com.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (4)
Login
Forgot your account info?

tinyurl.com also has prefsBy mvgfr on March 14, 2009, 6:09 pmyou can turn on the preview feature by default; handy

Reply | Read entire comment

DO NOT USEBy Anonymous on March 16, 2009, 11:27 amThere really is not place for such a service. One has to ask, do the benefits outweigh the costs? I decided No, a long time ago. One must place a lot of trust...

Reply | Read entire comment

Easy to say, difficult to implementBy Anon on March 16, 2009, 6:21 pmUnfortunatly, many of the web-based email services like Yahoo, Google and MSN will break the link if the URL has a carriage return in it. And since not everyone...

Reply | Read entire comment

previewBy Anonymous on March 17, 2009, 7:24 amwhat about http://www.tiny.cc/ .. no preview. is available!

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed