Skip to content

🧩 Feature Request: Link Shortener Handling #9

Description

@jaspermayone

Goal:
Detect and expand shortened URLs to reveal their final destination, and include a flag in the response indicating whether the original URL was shortened.


📋 Description

Many phishing attempts use link shorteners to obscure malicious destinations. To improve detection, we want to:

  • Detect if a URL is a known shortener (e.g., bit.ly, t.co, tinyurl.com).
  • Follow redirects to unshorten the URL.
  • Return the final destination URL.
  • Add a boolean field in the response (e.g., wasShortened: true) to indicate if the original URL was shortened.

🛠 Suggested Implementation

A basic implementation using Node.js might look like this:

const https = require('https');
const http = require('http');

function unshorten(shortUrl) {
  return new Promise((resolve, reject) => {
    const client = shortUrl.startsWith('https') ? https : http;

    const options = {
      method: 'HEAD',
      followAllRedirects: true,
      maxRedirects: 5,
    };

    const req = client.request(shortUrl, options, (res) => {
      if (res.statusCode >= 300 && res.statusCode < 400) {
        resolve(res.headers.location);
      } else if (res.statusCode === 200) {
        resolve(res.req.res.responseUrl || shortUrl);
      } else {
        reject(new Error(`Unexpected status code: ${res.statusCode}`));
      }
    });

    req.on('error', (error) => reject(error));
    req.end();
  });
}

This can be integrated into the scanning pipeline, with logic to check if the domain is a known shortener.


✅ Acceptance Criteria

  • Detects known link shorteners.
  • If shortener was used, report to the appropriate contact at shortener company (See 📌 Feature: Automated External Reporting #8 for a working database of link shortener contacts, etc)
  • Follows redirects to final destination.
  • Adds wasShortened flag to response.
  • Handles errors gracefully (e.g., unreachable URLs, infinite redirects).
  • Includes unit tests for common shorteners.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    issue-boardThis tag does cool automation things!

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions