Modern Australian
Men's Weekly

.

We analysed the entire web and found a cybersecurity threat lurking in plain sight

  • Written by Kevin Saric, Computer Scientist & Mechatronic Engineer, CSIRO
We analysed the entire web and found a cybersecurity threat lurking in plain sight

Our latest research has found that clickable links on websites can often be redirected to malicious destinations. We call these “hijackable hyperlinks” and have found them by the millions across the whole of the web, including on trusted websites.

Our paper, published at the 2024 Web Conference, shows that cybersecurity threats on the web can be exploited at a drastically greater scale than previously thought.

Concerningly, we found these hijackable hyperlinks on the websites of large companies, religious organisations, financial firms and even governments. The hyperlinks on these websites can be hijacked without triggering any alarms. Only vigilant – some might say paranoid – users would avoid falling into these traps.

If we were able to find these vulnerabilities across the web, so can others. Here’s what you need to know.

What are hijackable hyperlinks?

If you make a typo when entering your bank’s web address, you might accidentally end up on a phishing site – one that impersonates, or “spoofs”, your bank’s website to steal your personal info.

If you’re in a rush and don’t inspect the website closely, you may enter sensitive personal details and pay a steep price for your mistake. This could include identity theft, account compromise or financial loss.

Something even more dangerous happens when programmers mistype web addresses in their code. There’s a chance their typo will direct users to an internet domain that has never been purchased. We call these phantom domains.

For example, a programmer making a link to theconversation.com might accidentally link to tehconversation.com – note the misspelling. If the mistyped domain has never been purchased, someone could come along and buy that phantom domain for around A$10, hijacking the inbound traffic. In these cases, the price of programmers’ mistakes is paid by the users.

These programmer linking errors don’t just risk directing users to phishing or spoofing sites. Hijacked traffic can be directed towards a range of traps, including malicious scripts, misinformation, offensive content, viruses and any other hacks the future will bring.

Over half a million phantom domains

Using high-performance computing clusters, we processed the whole browsable web for these vulnerabilities. At a scale never seen in research, in total we analysed over 10,000 hard drives’ worth of data.

Doing so, we found over 572,000 phantom domains. The hijackable hyperlinks directing users to them were found on many trusted websites. In a twist of irony, this even included web-based software designed to enforce privacy legislation on websites.

We investigated what errors caused these vulnerabilities and categorised them. Most were caused by typos in hyperlinks, but we also found another type of programmer-generated vulnerability: placeholder domains.

When programmers develop a website that does not yet have a specific domain, they often enter links to a phantom domain with the expectation the links will be fixed later.

We found this to be common with website design templates, where the aesthetic components of a website are purchased from another programmer rather than developed in-house. When the design template is later installed on a website, the phantom domains are often not updated, making links to them hijackable.

To determine if hijackable hyperlinks could be exploited in practice, we purchased 51 of the phantom domains they point to and passively observed the inbound traffic. From this, we detected substantial traffic coming from the hijacked links. Compared to similar new domains that lacked hijacked links, 88% of our phantom domains got more traffic, with up to ten times more visitors.

A man with a black beard and glasses looks at his smartphone while frowning, sitting at a cafe with his laptop.
Staying vigilant on the web is your best protection against falling for hijacked links. GaduLab/Shutterstock

What can be done?

For average web users, awareness is key. Links cannot be trusted. Be vigilant.

For those in charge of companies and their websites, we suggest several technical countermeasures. The simplest solution is for website operators to “crawl” their websites for broken links. Countless free tools are available for doing so. If any broken links are found, fix them before they are hijacked.

We, the Web

British scientist Sir Tim Berners-Lee first proposed the web at CERN in 1989. In his earliest description of it – still widely available on the web as a testament to itself – there is a section titled “non requirements”, where security is addressed. This section includes the fateful phrase:

[Data security is] of secondary importance at CERN, where information exchange is still more important.

While this was true of CERN in 1989, the web is now the primary information exchange medium of the modern age.

We have come to treat the web as an external component of our own brains. This is evidenced by the popularity of large language models like ChatGPT, which themselves are trained on data from the web.

As our dependence deepens, it might be time to mentally re-categorise web data security from “non requirements” to “important requirements”.

Authors: Kevin Saric, Computer Scientist & Mechatronic Engineer, CSIRO

Read more https://theconversation.com/we-analysed-the-entire-web-and-found-a-cybersecurity-threat-lurking-in-plain-sight-233240

Elevate your Perth workspace: Sleek tech with managed IT Services

In today's fast-paced business environment, having a reliable and efficient IT infrastructure is no longer a luxury, it's a necessity. For businesse...

7 Ways a Luxury Australian Cruise Transforms Your Travel Expectations

Dreaming of your next holiday? Forget the crowded tourist traps and consider something truly special: a luxury australian cruise. More than just a ...

How Polycarbonate Became the Backbone of Modern Australian Design

The design landscape in Australia has been audacious, innovative and climate-conscious at all times. Design in this area is all about striking a balan...

Affordable Invisalign in Bangkok Why Australians Are Choosing Thailand

More Australians are investing in Invisalign to straighten their teeth, but the treatment in Australia can cost thousands of dollars and often takes m...

Designing a Tranquil Oasis in Your Backyard

Nothing beats a warm summer evening spent in a gorgeous backyard. The backyard is the perfect space to unwind and spend some of the most magical momen...

How a Well-Designed Gym Can Improve Your Performance

Have you ever entered a gym that just feels off and couldn’t focus on your workout? Maybe it’s the layout that was weird, or the lack of natural l...

Wellness Checkups at Work: Key to Employee Happiness and Higher Output

Employee wellness programs are reshaping how companies think about productivity and satisfaction. When people feel healthy, they perform better, sta...

Experience the Elegance of Plantation Shutter Blinds: Enhance Your Décor Today

When it comes to elevating your home’s interior, few window treatments combine sophistication and practicality as effortlessly as plantation shutter...

Common Questions Women Are Afraid to Ask Their Gynaecologist (and Honest Answers)

Visiting your gynaecologist isn’t always easy. Even though reproductive and sexual health are essential parts of overall wellbeing, many women fee...

Designing Homes for Coastal Climates – How to Handle Salt, Humidity, and Strong Winds in Building Materials

Living by the ocean is a dream for many Australians, offering breathtaking views, refreshing sea breezes, and a relaxed lifestyle that’s hard to b...

This OT Week, Australia’s occupational therapists are done staying quiet

Occupational Therapy Week is typically a time to celebrate the difference occupational therapists make in people’s lives. But this year, many sa...

Melbourne EMDR Clinic Sees Growing Interest in Patients with Depression

Depression is a common mental health condition affecting around 1 in 7 Australians. It is typically diagnosed when an individual has experienced a p...

Proactive approaches to mental wellbeing

Life gets busy quickly. For many adults, each week is a constant mix of work commitments, raising kids, managing a household, settling bills, catching...

The Power of Giving Back: How Volunteering Shapes Your Mindset

To say the least, volunteering can maximally change the way you see the world. Period. When you step into someone else’s shoes, even for a few hours...

How to Level Up Your Workouts with Simple Home Equipment

Working out at home has reached the peak of its popularity. Whether you’re short on time or simply prefer the comfort of your own space, home traini...

How to Prepare Financially for Buying a Home

Buying a house is one of the biggest and most exciting money choices you'll ever make. It means you stop giving rent money to someone else and start b...

Why Choosing Local Lawyers in Brisbane Can Make All the Difference

When it comes to legal matters, your choice of representation can influence both the outcome and overall experience. Working with local lawyers in B...

Restoring Volume and Style with Human Hair Toppers for Women

Hair plays a significant role in confidence and self-expression, but thinning hair and hair loss can affect women at any stage of life. While wigs p...