Goal:
Detect and expand shortened URLs to reveal their final destination, and include a flag in the response indicating whether the original URL was shortened.
📋 Description
Many phishing attempts use link shorteners to obscure malicious destinations. To improve detection, we want to:
- Detect if a URL is a known shortener (e.g., bit.ly, t.co, tinyurl.com).
- Follow redirects to unshorten the URL.
- Return the final destination URL.
- Add a boolean field in the response (e.g.,
wasShortened: true) to indicate if the original URL was shortened.
🛠 Suggested Implementation
A basic implementation using Node.js might look like this:
const https = require('https');
const http = require('http');
function unshorten(shortUrl) {
return new Promise((resolve, reject) => {
const client = shortUrl.startsWith('https') ? https : http;
const options = {
method: 'HEAD',
followAllRedirects: true,
maxRedirects: 5,
};
const req = client.request(shortUrl, options, (res) => {
if (res.statusCode >= 300 && res.statusCode < 400) {
resolve(res.headers.location);
} else if (res.statusCode === 200) {
resolve(res.req.res.responseUrl || shortUrl);
} else {
reject(new Error(`Unexpected status code: ${res.statusCode}`));
}
});
req.on('error', (error) => reject(error));
req.end();
});
}
This can be integrated into the scanning pipeline, with logic to check if the domain is a known shortener.
✅ Acceptance Criteria
Goal:
Detect and expand shortened URLs to reveal their final destination, and include a flag in the response indicating whether the original URL was shortened.
📋 Description
Many phishing attempts use link shorteners to obscure malicious destinations. To improve detection, we want to:
wasShortened: true) to indicate if the original URL was shortened.🛠 Suggested Implementation
A basic implementation using Node.js might look like this:
This can be integrated into the scanning pipeline, with logic to check if the domain is a known shortener.
✅ Acceptance Criteria
wasShortenedflag to response.