A Defensive Computing Checklist    by Michael Horowitz
HOME | About | Domain Names | VPNs | Rules of the Road | DC Presentation | ChangeLog | Stats |

LINK EXPANDERS, URL EXPANDERS

The problem with URL shorteners (aka link shorteners), such as bit.ly, Twitter's t.co and Flipboard's flip.it, is that they hide the ultimate destination of a link. You can check where a shortened link actually leads using assorted Link Expanders (aka URL Expanders).

There are a number of reasons to know the ultimate destination of a link. One reason that I often run into is tracking. I find that many links are blocked by assorted ad and tracker blocking systems. I use multiple blocking systems: a browser plug-in, a VPN feature and/or DNS. When a link is blocked (usually a tracking web page fails to load), the Link Expander will show me the ultimate destination URL, which I can then go to manually.

November 12, 2022: This topic used to have a single list, now there are two. This happened when someone I know was sent a malicious email message that included this link (without the spaces of course)
    https:// bit.ly / 3tlrN22

Testing it with different link expanders showed different results. This link gets re-directed more than once. The first re-direct is to sherlock.scribblelive.com and then to pollongq.world before ending up at google.com, of all places. Some link expanders only show the ultimate destination, hiding the intermediate re-direct URLS. Better ones showed the intermediate re-direct locations.

This is an important difference as the ultimate destination was a safe web site, the malicious URLs were in the middle. The re-direction is apparently programmed to tell the difference between an URL expander and an actual victim. Thus, an URL expander that only shows the ultimate destination is, in effect, lying.

EXPANDERS THAT SHOW INTERMEDIATE URLS

  1. urlscan.io is my favorite (see below for more)
  2. expandurl.net   See screen shot
  3. Redirect Checker from WhatsmyDNS.net

EXPANDERS THAT ONLY SHOW THE FINAL URL

The URL expander GetLinkInfo.com was in a category of its own. It showed the first re-direct, then suffered an error.

WEBSITE RATING SERVICES

Another aspect of this is whether the final destination of a shortened URL is malicious or not. Some URL expanders include this information but these services are dedicated to evaluating websites. And, they also do Link Expanding.

VirusTotal is, perhaps, most famous for evaluating virus software on Windows, but it also offers evaluations of website safety from 90 different sources. In my test case, 4 sources said the URL was malicious and 86 said it was safe. However, it is not clear which URL they are evaluating. It reports that the ultimate destination is google.com which, when evaluated on its own is considered perfectly safe by all 90 sources. The re-direction chain is available in the Details tab.

The best result, with my test URL, was from urlscan.io. See it here. URLscan was the only service that did not report google.com as the ultimate destination. It did show the same first two re-directs (sherlock.scribblelive.com and pollongq.world) as all the other services, but it showed the ultimate destination as trytips-4result.world which it flagged as malicious. You can see the re-direction trail here and here.

- - - - - - - - - - - - - - - - -
In January 2020, Simon Frey (of unshort.link) introduced an extension for Firefox and Chrome that checks short links against a blacklist and prevents them from tracking you.

 

 This page: 5 views per day (over 844 days)   Total views: 4,595   Created: October 23, 2022
This Page
Last Updated

September 16, 2024
Site Page
Views TOTAL

 1,097,387
Site Page
Views TODAY

  18
Website by
Michael Horowitz
@defensivecomput
top
Copyright 2019 - 2025