Facebook crawls links in PDFs you send in Messenger
1–10 of 165 posts
Re: Facebook crawls links in PDFs you send in Messenger
#2Would be interesting to see if Facebook has a maximum number of links it'll follow.
Re: Facebook crawls links in PDFs you send in Messenger
#3Could someone effectively DOS another site using this method by including a bunch of links that generate a lot of load? Would be interesting to see if Facebook has a maximum number of links it'll follow.
Re: Facebook crawls links in PDFs you send in Messenger
#4Re: Facebook crawls links in PDFs you send in Messenger
#5Re: Facebook crawls links in PDFs you send in Messenger
#6I can totally understand scanning a PDF for links to look for malicious links to protect users.
But that wouldn't involve actual HTTP requests to them.
I'm struggling to imagine what purpose this could have.
Re: Facebook crawls links in PDFs you send in Messenger
#7Sidenote i wonder why FB doesnt launch a search engine since they crawl most of the web anyways
Re: Facebook crawls links in PDFs you send in Messenger
#8Huh, but why? I can totally understand scanning a PDF for links to look for malicious links to protect users. But that wouldn't involve actual HTTP requests to them. I'm struggling to imagine what purpose this could have.
Re: Facebook crawls links in PDFs you send in Messenger
#9Huh, but why? I can totally understand scanning a PDF for links to look for malicious links to protect users. But that wouldn't involve actual HTTP requests to them. I'm struggling to imagine what purpose this could have.
I'm sure if they're pulling data to do this analysis, it's not the only analysis they're doing.
Re: Facebook crawls links in PDFs you send in Messenger
#10Huh, but why? I can totally understand scanning a PDF for links to look for malicious links to protect users. But that wouldn't involve actual HTTP requests to them. I'm struggling to imagine what purpose this could have.
One of the things that phishers and others do is use link wrapping and other services to hide malicious links. So, I get something.wordpress.com/something-clean. I then put in an HTML or JS redirect on that page to something malicious. Given that browsers don't warn about HTTP, HTML, or JS redirects, it's an easy way for scammers to get around a list of malicious pages.
These kinds of attacks are very common in the email space.