Print Print    Close Close

Google Maps is being abused by scammers

By ,

Published May 02, 2018

PCmag
0ce23963-google maps

File photo: Google Maps application is displayed on a smartphone in Seoul, South Korea, in this photo illustration on August 24, 2016. REUTERS/Kim Hong-Ji TPX IMAGES OF

Last month, Google announced that it would be shutting down the goo.gl URL shortening service and replacing it with Firebase Dynamic Links. But before those short links disappear, scammers continue to take full advantage of them with a little help from Google Maps.

Security company Sophos discovered that scammers are using a vulnerability in Google Maps URLs. It's known as an open redirect vulnerability and allows an otherwise safe link to redirect to another page without the user's knowledge. It also bypasses all the safety checks Google performs when creating a new short URL.

What the scammers want to achieve is a short URL that leads directly to their scam site where you'll be bombarded with offers to buy pills, or worse, an attempt will be made to compromise your PC. Linking directly to a scam site will result in Google's automated checks sounding alarm bells and refusing the link, so the scammers need a legitimate middleman. It turns out Google Maps works perfectly because of the open redirect vulnerability.

As an example, this is a legitimate Google Maps URL which has been modified to redirect to example.org: https://maps.app.goo.gl/?link=https%3A%2F%2Fexample.org. The link would pass any URL shortening service tests, but would when clicked load a completely different web page than the intended one.

More From PCmag

  • Blockchain and Robots: Buzzy, But Not Yet VC Blockbusters
  • Facebook Looks to 'Stories' Feature, Amid News Feed Revamp
  • It's Time to Stop It With the Terrible Passwords
  • Zuck Takes the Stage: Everything You Missed From Facebook F8

Modifying the link is easy for the scammers to do and can't easily be detected. The fix is up to Google, who has apparently known about the vulnerability since September last year.

This article originally appeared on PCMag.com.

Print Print    Close Close

URL

https://www.foxnews.com/tech/google-maps-is-being-abused-by-scammers

  • Home
  • Video
  • Politics
  • U.S.
  • Opinion
  • Entertainment
  • Tech
  • Science
  • Health
  • Travel
  • Lifestyle
  • World
  • Sports
  • Weather
  • Privacy
  • Terms

This material may not be published, broadcast, rewritten, or redistributed. © FOX News Network, LLC. All rights reserved. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset. Powered and implemented by FactSet Digital Solutions. Legal Statement. Mutual Fund and ETF data provided by LSEG. Do Not Sell my Personal Information - New Terms of Use - FAQ