You can not simply publicly access private secure links, can you?

You can not simply publicly access private secure links, can you?

2/13/2025

notes

i've spent a good amount of time avoiding creating these unauthenticated links for many of these reasons laid out in the article.

it was nice to have a coherent outline steps for why these links may not be what you want to create.

with that said, there is a have your cake and eat it too with a few small investments like auto-expiration, rate limiting and more (assuming you don't end up sacrificing the main UX goals entirely)

link

https://vin01.github.io/piptagole/security-tools/soar/urlscan/hybrid-analysis/data-leaks/urlscan.io/cloudflare-radar%22/2024/03/07/url-database-leaks-private-urls.html

summary

Popular malware/url analysis tools like urlscan.io, Hybrid Analysis and Cloudflare radar url scanner store a large number of links for intelligence gathering and sharing. It is however not so widely known that these services also store a large amount of private and sensitive links, thanks to: Sensitive links mistakenly submitted by users for scanning unaware that these are public information Misconfigured scanners and extensions submitting private links scanned from emails as public data

tags

urlscan.io ꞏ Hybrid Analysis ꞏ Cloudflare radar ꞏ private links ꞏ data leaks ꞏ security