Whenever a link is posted to Facebook or other social media sites, the site will likely scan the destination page for Open Graph tags [1]. These tags may provide a link to an image to be displayed, or alternate URLs to be displayed and other meta tags.
(URLs obfuscated to protect the click-happy)
For example, the following short link hxxps://goo. gl/ 8k64yS posted to Facebook recently links tohxxp: //storage. googleapis. com/1501853956/1501853956.html, which in turn returns the following content:
meta name=viewport content=width=device-width, initial-scale=1
meta property=og:url content=http://YOUTU.BE/ /
meta property=og:type content=article /
meta property=og:title content=Video /
meta property=og:description content=355,857 View /
meta property=og:image content=https://www.youtube.com/yts/img/yt_1200-vfl4C3T0K.png /
style }/style
iframe src=hxxp:// smarturl. it/uvita onload=
the meta og: tags will tell Facebook to display a YouTube logo (og:image), and the text 355,857 View (og:description), making this look like a legitimate link to YouTube. Instead, the user is redirected to a second URL shortener in this case. smarturl.it width:300px" />
[1]http://ogp.me
---
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS Technology Institute
STI|Twitter|
Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.
Read more of this story at Slashdot.
Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.
Read more of this story at Slashdot.
Read more of this story at Slashdot.