Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Dropbox fixes hyperlink flaw

by The Gurus
May 7, 2014
in Editor's News
Share on FacebookShare on Twitter

Dropbox has squashed a bug which impacted shared links to files that contained hyperlinks.
 
According to a blog by Aditya Agarwal, vice president of engineering at Dropbox, it has taken steps to address this issue and users do not need to take any further action. He explained that in the instance, if a Dropbox user shared a link to a document that contained a hyperlink to a third-party website and recipient clicked on that hyperlink in the document, the original shared link to the third-party website could be accessed by the webmaster of the third-party website.
 
The research by IntraLinks was reported yesterday, but Agarwal said Dropbox was unaware of any abuse of this vulnerability, but it has disabled access to shared links until further notice and it is working to restore links that were not susceptible to this vulnerability.
 
“We realise that many of your workflows depend on shared links, and we apologise for the inconvenience. We’ll continue working hard to make sure your stuff is safe and keep you updated on any new developments,” he said.
 
IntraLinks said it reported the issue to Dropbox in November 2013, but Dropbox had not determined it to be a vulnerability until it was widely reported by the media yesterday.
 
TK Keanini, CTO of Lancope, said that this was the reality of the cloud, where the good news is that you can always access anything, anytime, anywhere – the bad news is sometimes the bad guys can do the same.
 
“When people think about Usability Design, they also need to think about security. We want to make it easier, not harder for the user to manage their own security settings,” he said. “Designers will make mistakes along the way, but we must learn from these mistakes and correct them so that others can avoid them too.”
 
He said that the fundamental problem with the link share issue was that without a second factor of authentication, it should not be treated as anything but a public resource no matter how many people know.
 
“These services like Dropbox are awesome for productivity, but with this power comes responsibility. Users need to take more responsibility for the security of their files and demand that features be added so that they can manage their security better. Any other strategy simply will not scale to the internet.”
 
Rob Sobers, director of Varonis, said: “The primary danger of shared links, as implemented by most cloud services, is that they rely solely on security through obscurity. While obscurity is better than nothing, it’s certainly not great protection as we’ve seen.
 
“Couple this with the likelihood of user or admin misconfiguration due to lack of understanding and poor user interfaces and, as we’ve seen with Box, Amazon, and now Dropbox risk is high, so people should proceed with caution.”

Tags: CloudDropboxVulnerability
ShareTweet
Previous Post

FireEye to boost forensic capabilities with nPulse acquisition

Next Post

Missed the flashing light?

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol