One of the websites I look after was taking content provided by third parties and adding it into the website. I was working my way through some posts when I came across a strange looking link hidden under an innocent looking title.
The editor in this case had just cut and paste everything, and had not tested it. There were two cases, one went to a newsletter mailing website and then was diverted to the actual site. In this case the actual site was simply a holding page, and the fact that the link went to that site via a third party meant it was logged. Of course we do not know what else happened on the way. The link text contained Yurts for Life, but the link was actually going to here:
http://manorfarm.us10.list-manage1.com/track/click=eea270f45b87b007e97fa644b&id=ebeb93cbe5&e=c391a34f71
Which is not going to Yurts for Life. The behaviour of the link when clicked went somewhere, then to somewhere else.
The link was provided in good faith, however if nobody checks these things it can be simply passed down the chain. In this case it is probably completely innocent, however what if it wasn’t? Would you know; the fact you have put this on your site, exposes it to all of your visitors.
Test it when you publish it
Simply placing your cursor over a link without clicking will generally show you where it is going. If it looks dodgy, remove it!
Solution: Check your links, and if they don’t go direct to the target site, or the target site does not exist, remove the link if you do not know what it is doing.
Now this link was in plain text so we can draw some conclusions as to what is happening.
The Obfuscated Link
Or shortened link. There is a legitimate reason why you might wish to reduce a very long URL to a few characters. The main one is Twitter which only allows you to have a few characters, another example is Google maps where the URL is very long.
An example shortened link looks like this:
https://goo.gl/maps/nLXeX5BoQbr
In this case we can guess it is Google Maps. The link is ok, it will show you a community centre in Amersham, Bucks. The original link was much longer.
There are others though that you would not have a clue where they go to:
http://bit.ly/2mXCXu8 < that one goes to the home page for this website if you want to check it.
If someone passes a shortened link to you, you need to ask yourself why? Hackers often use shortened links in spoofed emails to hide where a link really goes to. An email arrives and looks official, and if you click on the link it will take you to a page that asks for your username and password to some account. Of course you have to click on it to find out where it goes to. When you do that other things may happen. For example it looks like your normal login page, but it is a hacker stealing passwords and user names. Or you have simply acknowledged that your email address is live, because you responded, or you may have inadvertently downloaded something onto your computer. It is worth being cautious, for you and your user’s benefits.
I have seen several examples this week in spam mail. If you see a link that probably need not be there, or does not look right, go back to the person providing the content and enter the proper URL, if only to protect your users.