Google blocking all bit.ly links as malicious

  • 25 October 2014
  • 6 replies
  • 1 view

Userlevel 7
Badge +3
 By Graham Cluley
 
 
It seems bit.ly has made its way onto Google’s list of sites that aren’t safe to browse to.
Let’s hope it gets fixed soon, because boy oh boy it’s going to be inconvenient.
 
 http://grahamcluley.com/2014/10/google-blocking-bit-ly-links-malicious/
 
and Martin Brinkmann:
 
 http://www.ghacks.net/2014/10/25/google-blocks-bit-ly-chrome-and-firefox-affected/
 
Bitly is a popular url shortening service that is widely used and according to Alexa one of the top 4000 websites in the world. It can be used by anyone to turn any link into a shorter version that looks similar to this one: http://bit.ly/1dNVPAW
If you have tried to open the main Bitly website recently or clicked on a link that was shortened by others using the service you may have received a notification in your browser that access to the website has been blocked.

6 replies

Userlevel 7
Badge +3
Not blocked anymore....
     
What is the current listing status for bit.ly?
This site is not currently listed as suspicious.        https://www.google.com/safebrowsing/diagnostic?site=bit.ly&hl=en
Userlevel 7
Glad they have that fixed quickly.... that would be a huge problem if it was to remain blocked.
Userlevel 7
Badge +3
@ wrote:
Glad they have that fixed quickly.... that would be a huge problem if it was to remain blocked.
A lot use those shortened links, especially on Twitter and Facebook, and mostly for convenience and compactness, but personally I regard them as potentially representing a risk, and would never randomly click one, and instead use an unshortening service to extract the URL for identification.
 
I don't like shortened URLs, simple as that.
 
Userlevel 7
Oh I agree in principle there.  I will click on the shortened link ONLY if it is coming from a trusted source, and I do not mean just someone on my Friends List.  Posts from Webroot, NASA, CNN, well, you get the idea.  I will click those.
 
The rest, I will run through verifying BEFORE I open the actual link.
Userlevel 7
So.................my question is use another browser and also another search engine such as start page along with WSA you should be good to go..
Userlevel 7
Badge +3
Vigilance and caution best advised imo, despite subsequent withdrawal of warnings:
 
 "Unfortunately, Google is not completely wrong with this one (but likely a bit excessive, time will tell). We constantly see malware injection on websites leveraging shortened URL links. Here is an example of what we mean, this payload was found in a compromised website:"
 
and:
 
 "Additionally, if you leverage the shortener in your own website this could be impactful to you as your website could get inadvertently blacklisted for loading a blacklisted website. Something to be mindful of. The good news is that the blacklist will be for the shortener, so removing it will address the problem, but the bad news is that most end-users won’t read the details and assume it’s you."
 
from: http://blog.sucuri.net/2014/10/bit-ly-blacklisted-by-google-safe-browsing.html

Reply