{"id":24091,"date":"2009-01-31T00:00:00","date_gmt":"2009-01-31T00:00:00","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/open-redirect-urls-is-your-site-being-abused\/"},"modified":"2009-01-31T00:00:00","modified_gmt":"2009-01-31T00:00:00","slug":"open-redirect-urls-is-your-site-being-abused","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/open-redirect-urls-is-your-site-being-abused\/","title":{"rendered":"Open redirect URLs: Is your site being abused?"},"content":{"rendered":"<p class=\"gargardate\">Saturday, January 31, 2009<\/p>\n<p>\n  No one wants malware or spammy URLs inserted onto their domain, which is why we all try to follow<br \/>\n  <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/quick-security-checklist-for-webmasters\/\">good security practices<\/a>.<br \/>\n  But what if there were a way for spammers to take advantage of your site, without ever setting a<br \/>\n  virtual foot in your server? There is, by <b>abusing open redirect URLs<\/b>.\n<\/p>\n<p>\n  Webmasters face a number of situations where it&#8217;s helpful to redirect users to another page.<br \/>\n  Unfortunately, redirects left open to any arbitrary destination can be abused. This is a<br \/>\n  particularly onerous form of abuse because it takes advantage of your site&#8217;s functionality rather<br \/>\n  than exploiting a simple bug or security flaw. Spammers hope to use your domain as a temporary<br \/>\n  &#8220;landing page&#8221; to trick email users, searchers and search engines into following links which<br \/>\n  appear to be pointing to your site, but actually redirect to their spammy site.\n<\/p>\n<p>\n  We at Google are working hard to keep the abused URLs out of our index, but it&#8217;s important for you<br \/>\n  to make sure your site is not being used in this way. Chances are you don&#8217;t want users finding<br \/>\n  URLs on your domain that push them to a screen full of unwanted porn, nasty viruses and malware,<br \/>\n  or phishing attempts. Spammers will generate links to make the redirects appear in search results,<br \/>\n  and these links tend to come from bad neighborhoods you don&#8217;t want to be associated with.\n<\/p>\n<p>\n  This sort of abuse has become relatively common lately so we wanted to get the word out to you and<br \/>\n  your fellow webmasters. First we&#8217;ll give some examples of redirects that are actively being<br \/>\n  abused, then we&#8217;ll talk about how to find out if your site is being abused and what to do about<br \/>\n  it.\n<\/p>\n<h2 id=\"redirects-being-abused-by-spammers\" tabindex=\"-1\"> Redirects being abused by spammers<\/h2>\n<p>\n  We have noticed spammers going after a wide range of websites, from large well-known companies to<br \/>\n  small local government agencies. The list below is a sample of the kinds of redirect we have seen<br \/>\n  used. These are all perfectly legitimate techniques, but if they&#8217;re used on your site you should<br \/>\n  watch out for abuse.\n<\/p>\n<ul>\n<li>\n    Scripts that <b>redirect users to a file on the server<\/b>\u2014such as a PDF document\u2014can sometimes<br \/>\n    be vulnerable. If you use a content management system (CMS) that allows you to upload files,<br \/>\n    you might want to make sure the links go straight to the file, rather than going through a<br \/>\n    redirect. This includes any redirects you might have in the downloads section of your site.<br \/>\n    Watch out for links like this:<br \/>\n    <code>example.com\/go.php?url=<b>example.com\/ie\/ie40\/download\/<\/b><\/code><\/p>\n<li>\n    <b>Internal site search result pages<\/b> sometimes have automatic redirect options that could be<br \/>\n    vulnerable. Look for patterns like this, where users are automatically sent to any page after<br \/>\n    the <code>url=<\/code> parameter:<br \/>\n    <code>example.com\/search?q=user+search+keywords&amp;url=<\/code>\n  <\/li>\n<li>\n    Systems to <b>track clicks<\/b> for affiliate programs, ad programs, or site statistics might be<br \/>\n    open as well. Some example URLs include:<\/p>\n<div><\/div>\n<\/li>\n<li>\n    <b>Proxy sites<\/b>, though not always technically redirects, are designed to send users through<br \/>\n    to other sites and therefore can be vulnerable to this abuse. This includes those used by<br \/>\n    schools and libraries. For example:<br \/>\n    <code>proxy.example.com\/?url=<\/code>\n  <\/li>\n<li>\n    In some cases, <b>login pages<\/b> will redirect users back to the page they were trying to<br \/>\n    access. Look out for URL parameters like this:<br \/>\n    <code>example.com\/login?url=<\/code>\n  <\/li>\n<li>\n<li>\n      Scripts that put up an <b>interstitial page when users leave a site<\/b> can be abused. Lots of<br \/>\n      educational, government, and large corporate web sites do this to let users know that<br \/>\n      information found on outgoing links isn&#8217;t under their control. Look for URLs following<br \/>\n      patterns like this:<\/p>\n<div><\/div>\n<\/li>\n<\/ul>\n<h2 id=\"is-my-site-being-abused\" tabindex=\"-1\">Is my site being abused?<\/h2>\n<p>\n  Even if none of the patterns above look familiar, your site may have open redirects to keep an eye<br \/>\n  on. There are a number of ways to see if you are vulnerable, even if you are not a developer<br \/>\n  yourself.\n<\/p>\n<ul>\n<li>\n    Check if abused URLs are showing up in Google. Try a<br \/>\n    <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/site-search-operator\/\"><span>site:<\/span> search<\/a><br \/>\n    on your site to see if anything unfamiliar shows up in Google&#8217;s results for your site. You can<br \/>\n    add words to the query that are unlikely to appear in your content, such as commercial terms or<br \/>\n    adult language. If the query [site:example.com viagra] isn&#8217;t supposed to return any pages on<br \/>\n    your site and it does, that could be a problem. You can even automate these searches with<br \/>\n    <a href=\"https:\/\/www.google.com\/alerts\" class=\"external-link\">Google Alerts<\/a>.\n  <\/li>\n<li>\n    You can also watch out for strange queries showing up in the<br \/>\n    <a href=\"https:\/\/www.google.com\/support\/webmasters\/bin\/answer.py?answer=35252\" class=\"external-link\">Top search queries<\/a><br \/>\n    section of Webmaster Tools. If you have a site dedicated to the genealogy of the landed gentry,<br \/>\n    a large number of queries for porn, pills, or casinos might be a red flag. On the other hand, if<br \/>\n    you have a drug info site, you might not expect to see celebrities in your top queries. Keep an<br \/>\n    eye on the Message Center in Webmaster Tools for any messages from Google.\n  <\/li>\n<li>\n    Check your server logs or web analytics package for unfamiliar URL parameters (like<br \/>\n    <code>=http:<\/code> v\u0259 ya <code>=\/\/<\/code>) or spikes in traffic to redirect URLs on your site.<br \/>\n    You can also check the pages with external links in Webmaster Tools.\n  <\/li>\n<li>\n    Watch out for user complaints about content or malware that you know for sure can not be found<br \/>\n    on your site. Your users may have seen your domain in the URL before being redirected and<br \/>\n    assumed they were still on your site.\n  <\/li>\n<\/ul>\n<h2 id=\"what-you-can-do\" tabindex=\"-1\">What you can do<\/h2>\n<p>\n  Unfortunately there is no one easy way to make sure that your redirects aren&#8217;t exploited. An open<br \/>\n  redirect isn&#8217;t a bug or a security flaw in and of itself\u2014for some uses they have to be left fairly<br \/>\n  open. But there are a few things you can do to prevent your redirects from being abused or at<br \/>\n  least to make them less attractive targets. Some of these aren&#8217;t trivial; you may need to write<br \/>\n  some custom code or talk to your vendor about releasing a patch.\n<\/p>\n<ul>\n<li>\n    <b>Change the redirect code to check the referer<\/b>, since in most cases everyone coming to<br \/>\n    your redirect script legitimately should come from your site, not a search engine or elsewhere.<br \/>\n    You may need to be permissive, since some users&#8217; browsers may not report a referer, but if you<br \/>\n    know a user is coming from an external site you can stop or warn them.\n  <\/li>\n<li>\n    If your script should only ever send users to an internal page or file (for example, on a page<br \/>\n    with file downloads), you should <b>specifically disallow off-site redirects<\/b>.\n  <\/li>\n<li>\n    <b>Consider using an allowlist<\/b> of safe destinations. In this case your code would keep a<br \/>\n    record of all outgoing links, and then check to make sure the redirect is a legitimate<br \/>\n    destination before forwarding the user on.\n  <\/li>\n<li>\n    <b>Consider signing your redirects<\/b>. If your website does have a genuine need to provide URL<br \/>\n    redirects, you can<br \/>\n    <a href=\"https:\/\/en.wikipedia.org\/wiki\/HMAC\" class=\"external-link\">properly hash<\/a><br \/>\n    the destination URL and then include that cryptographic signature as another parameter when<br \/>\n    doing the redirect. That allows your own site to do URL redirection without opening your URL<br \/>\n    redirector to the general public.\n  <\/li>\n<li>\n    If your site is really not using it, just <b>disable or remove the redirect<\/b>. We have noticed<br \/>\n    a large number of sites where the only use of the redirect is by spammers\u2014it&#8217;s probably just a<br \/>\n    feature left turned on by default.\n  <\/li>\n<li>\n    <b>Use <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/robots-txt-intro\/\">robots.txt<\/a> to exclude search engines<\/b><br \/>\n    from the redirect scripts on your site. This won&#8217;t solve the problem completely, as attackers<br \/>\n    could still use your domain in email spam. Your site will be less attractive to attackers,<br \/>\n    though, and users won&#8217;t get tricked via web search results. If your redirect scripts reside in<br \/>\n    a subfolder with other scripts that don&#8217;t need to appear in search results, excluding the entire<br \/>\n    subfolder may even make it harder for spammers to find redirect scripts in the first place.\n  <\/li>\n<li>\n    You can also <b>use Webmaster Tools to<br \/>\n    <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/removals-overview\/\">remove URLs<\/a><\/b>. Chances are<br \/>\n    that the spammers have also hacked and abused other sites to generate links to the spammed<br \/>\n    section of your site. If you see suspicious sites or<br \/>\n    <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/keeping-comment-spam-off-your-site-and-away-from-users\/\">spammed forums<\/a><br \/>\n    linking in, you can<br \/>\n    <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/report-spam-phishing-or-malware\/\">report those to us,<\/a><br \/>\n    preferably with the<br \/>\n    <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/report-spam-phishing-or-malware\/\">verified spam report form in Webmaster Tools<\/a>.\n  <\/li>\n<\/ul>\n<p>\n  Open redirect abuse is a big issue right now but we think that the more webmasters know about it,<br \/>\n  the harder it will be for the bad guys to take advantage of unwary sites. Please you can leave any<br \/>\n  helpful tips in the comments below or discuss in our<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/community\" class=\"external-link\">Webmaster Help Forum<\/a>.\n<\/p>\n<p class=\"byline-author\">Written by Jason Morrison, Search Quality Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Saturday, January 31, 2009 No one wants malware or spammy URLs inserted onto their domain, which is why we all try to follow good security practices. But what if there were a way for spammers to take advantage of your site, without ever setting a virtual foot in your server? There is, by abusing open [&hellip;]<\/p>\n","protected":false},"menu_order":85725,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[665],"ar_kb_etiket":[],"class_list":["post-24091","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-blog"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24091\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/26670"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=24091"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=24091"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=24091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}