Snapchat, Bitly and Kik Messenger targeted by spammers

Bitly is working with Symantec to clean up malicious links, the result of API keys left visible on the Web

You have to give spammers credit for effort: Symantec found a spam campaign that manages to abuse three Web services at the same time.

It starts on Snapchat, where some users receive an unsolicited photo message asking the person to add a contact as a friend on Kik Messenger, an instant messaging application, wrote Satnam Narang, a security response manager at Symantec, on a company blog.

Snapchat apologized on Monday for spam problems, saying it was the consequence of a fast-growing service. It recommended that users only allowed their approved friends to send them photos rather than receive unsolicited ones.

Narang wrote that if the spammy contact is added on Kik, a spam "bot," or a program designed to automatically chat with contacts, would send some canned text and a link shortened by Bitly. The links lead to sites trying to sign up users for adult webcam entertainment.

Part of the spammy Bitly links may look familiar.

"Spammers have found a way to create their own links using branded short domains in order to entice users into a false sense of security," he wrote.

Symantec found Bitly links generated using customs domains owned by brands and companies such as USA Today, National Geographic, the New York Post, Red Hat and MIT News, among others.

Custom domains can be registered with Bitly, which then appends a unique identifier on the end of the shortened URL that leads a person to its full content. The spammers abused the custom domains through an API (application programming interface) configuration problem, which left the API key visible.

"Bitly has confirmed that some spammers obtained Bitly API keys belonging to various brands," Narang wrote.

Bitly wrote in an email to IDG News Service that it was working with Symantec on the problem and pointed to its API best practices guide. Because of similar problems, the AddThis social bookmarking service also stopped requiring its users to reveal their API key in plain text as part of its code embedded in a website.

"Public exposure of API keys gives anybody the ability to compromise accounts and, in this case, create short URLs using other people's domains," Narang wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags instant messagingsymantecantispamInternet-based applications and servicesBitlySnapChatKik

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Skywatcher Dobsonian 8″ Collapsible Telescope

Learn more >

Family Friendly

Whodunnit™ Duo-Scope MFL-007 Microscope Kit

Learn more >

Stocking Stuffer

Logitech Ultimate Ears Wonderboom 2 Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?