vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   Suggestion: Block links from shortening services (https://vborg.vbsupport.ru/showthread.php?t=227689)

BSMedia 11-10-2009 02:16 AM

Suggestion: Block links from shortening services
 
I suggest prohibiting the use of URL shortening services at vB.org.

URL's that are passed thru these shortening services can contain links to malicious content, spyware, warez and other garbage sites and server no other purpose other than to mask or conceal a links true identity. The propensity of doing bad, far out weighs any positives for using such a service

Not to mention the potential for "marketing gurus" to slide their affiliate links in.

Marco van Herwaarden 11-10-2009 03:53 AM

Personally i tend to agree with your suggestion. We had this discussion within staff some time ago and the result was that it was also used a lot for legit reasons by members and we would be limiting them too much if we would block these.

Paul M 11-10-2009 09:16 AM

Standard links can be used for exactly the same malicious purpose. Its not something unique to short links.

DeanLag 11-10-2009 11:48 AM

But the chances is that shortened URLs containing malicious content are high compared to a standard URL.
Prevention is better than cure.

I personally blacklisted the shortened URLs on my board for the same reason as OP mentionned; even if it never happened before.
Good suggestion OP!

BSMedia 11-10-2009 12:50 PM

Quote:

Originally Posted by Paul M (Post 1912306)
Standard links can be used for exactly the same malicious purpose. Its not something unique to short links.



i agree, but then the domain and site thats being linked to isn't masked and we can see where the link goes hence increasing our security and reducing the chance of being taken to a spyware inflicting site

EX: http://thisisabadsite.com/thatinstall/spyware.exe can be made to bit.ly/47cGv and no one will have a clue until people click and are infected

What is one good need for masking URL's on a site like vB.org however. There is no character limitation imposed on the length of posts, so there really isn't a need to hide the actual URL unless it was up to no good.

Paul M 11-10-2009 02:16 PM

On what proof do you base the statement that a short url is any more likely to point to malicious code.

I could just as easily post a link like http://mysite/alink and redirect that to malicious code.

If you dont want to follow such links then fine, thats your choice, I dont see why that should mean we block them.

BSMedia 11-10-2009 02:24 PM

okay.


All times are GMT. The time now is 03:56 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00953 seconds
  • Memory Usage 1,720KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (7)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete