Remove URL
article thumbnail

Using Legitimate GitHub URLs for Malware

Schneier on Security

The attacker is exploiting a property of GitHub: comments to a particular repo can contain files, and those files will be associated with the project in the URL. These URLs would also appear to belong to the company’s repositories, making them far more trustworthy.

Libraries 108
article thumbnail

X.com Automatically Changing Link Text but Not URLs

Schneier on Security

The problem is: (1) it changed any domain name that ended with “twitter.com,” and (2) it only changed the link’s appearance (anchortext), not the underlying URL. So if you were a clever phisher and registered fedetwitter.com, people would see the link as fedex.com, but it would send people to fedetwitter.com.

IT 103
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Facebook Is Now Encrypting Links to Prevent URL Stripping

Schneier on Security

Mozilla introduced support for URL stripping in Firefox 102 , which it launched in June 2022. Firefox users may enable URL stripping in all Firefox modes , but this requires manual configuration. Facebook has responded by encrypting the entire URL into a single ciphertext blob.

article thumbnail

Python URL parsing function flaw can enable command execution

Security Affairs

A severe vulnerability in the Python URL parsing function can be exploited to gain arbitrary file reads and command execution. Researchers warn of a high-severity security vulnerability, tracked as CVE-2023-24329 (CVSS score of 7.5), has been disclosed in the Python URL parsing function that could be exploited to bypass blocklisting methods.

article thumbnail

Beware of Spoofed Vanity URLs

KnowBe4

Researchers at Varonis warn that attackers are using customizable URLs (also known as vanity URLS) on SaaS services to craft more convincing phishing links. The attackers have used this technique for links created through Box, Zoom, and Google Docs and Forms.

Phishing 108
article thumbnail

Malicious URLs In Phishing Emails: Hover, Click and Inspect Again

KnowBe4

The most often recommended piece of anti-phishing advice is for all users to “hover” over a URL link before clicking on it. It is great advice.

Phishing 105
article thumbnail

URL Parsing Bugs Allow DoS, RCE, Spoofing & More

Threatpost

Dangerous security bugs stemming from widespread inconsistencies among 16 popular third-party URL-parsing libraries could affect a wide swath of web applications.

Libraries 115