Hacker Hits URL Shortening Service Cligs | eWeek

Hacker Hits URL Shortening Service Cligs

Written By
Brian Prince
Brian Prince
Jun 16, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cligs, a popular URL shortening service for Twitter users, was hacked recently in an attack that exploited a security hole to redirect 2.2 million URLs.

“Late last night/early this morning, a security hole in the Cligs editing functionality was discovered and was exploited by a malicious attacker,” according to a June 15 statement on the Cligs’ Website. “The attack edited most URLs on Cligs to point to a single URL hosted on freedomblogging.com.”

For Twitter users, URL shortening services such as TinyURL and Cligs have become a staple because they allow users to Tweet long Web addresses and stay within the character limit imposed on messages. Such services, however, have attracted the attention of security researchers and attackers alike.

Sophos raised the alarm over a phishing scam late last month that used a TinyURL link to lure users to a rogue site.

“It’s not yet apparent what the intentions were of the hackers [in the Cligs case], but they could have just as easily redirected millions of shortened urls to a Website hosting malware,” blogged Graham Cluley, senior technology consultant at Sophos. “That’s one of the reasons why it can be helpful to run a plug-in that will expand shortened urls before you click on them.”

“As an aside, we frequently see spammers abusing shortened url services to try and make life harder for anti-spam filters trying to determine if a link is going somewhere unsavoury,” he added.

According to Cligs, the attacker’s IP address appears to have come from Canada. The company identified the security hole yesterday and began the process of restoring the URLs back to their original destinations. However, the company admitted that its most recent backup is from early May, so all URLs created since then may be lost.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.