Before you could even be affected (to their knowledge), Dropbox has already fixed a security flaw. In a company blog post, Dropbox informed users that they found a security flaw coming from shared links through third-party websites. The issue comes from a third-party website’s access to referer headers when links are posted. But because of this, the links “can be inadvertently disclosed to unintended recipients.”
So for now, Dropbox has shutdown shared links that provide access to a user’s documents. And over the next few days, access will be restored after being verified.
Here is the method of attack according to Dropbox:
- A Dropbox user shares a link to a document that contains a hyperlink to a third-party website.
- The user, or an authorized recipient of the link, clicks on a hyperlink in the document.
- At that point, the referer header discloses the original shared link to the third-party website.
- Someone with access to that header, such as the webmaster of the third-party website, could then access the link to the shared document.
Source: Dropbox
Come comment on this article: Dropbox issues patch to avoid any abuse of shared links security flaw
Android Match

Post a Comment