Active Articles: 2038
Total Categories: 16
Sub Categories:616
![]() |
|
RSS Security |
|
| Date Added: January 05, 2007 11:59:37 PM | |
| Author: S. Housley | |
| Category: Online Communities & Networks: RSS | |
Security Implications Related to RSS. As RSS gains momentum security fears loom large. As publishers are quickly finding innovative uses for RSS feeds, hackers are taking notice. The power and extendibility of RSS in its simplest form is also its achilles heel. The expansion capabilities of the RSS specification, specifically the ""enclosure"" field which has launched the podcasting phenomenon, is where the vulnerabilities lie. The enclosure field in itself is not the problem, in fact the majority of RSS feeds do not even use the enclosure tag. The enclosure tag is essentially used to link to file types, things like images, word documents, mp3 files, power point presentations, and executables and can be thought of in similar terms to email attachments. The fact that RSS can be used to distribute these file types has opened a myriad of doors to users of the syndication standard, but also has created cause for concern. Most people do not feel that the risk is significant because people ""choose"" the content that they receive, and while it might make the distribution of malware, viruses and spy applications via RSS less prevalent, their is still the inherent risk of a infected file being distributed. The problem is one of both technology and lack of education. The danger lies in the fact that many RSS readers, news aggregators, or pod-catchers automatically download the information contained in the enclosure field regardless of its file type or source. Most RSS developers acknowledge the risks associated with the enclosure field, but few have had the forethought to include filtering, screening or authentication capabilities and many automatically download enclosures. Nick Bradbury of Bradsoft/NewsGator seems to be proactive, designing FeedDemon with security in mind. FeedDemon uses an editable safelist of file types as well as allowing users to monitor what files are automatically downloaded. FeedDemon also contains hard-coded warnings related to specific file types. Developers of ByteScout took a different approach to the handling of enclosure files, ByteScout does not automatically download anything without user intervention for each download. Unfortunately, not all RSS readers, aggregators and podcatchers consider the possible security implications associated with RSS feeds and podcasts, some will automatically download enclosures without warning or any thoughts of security. Be sure to examine how your RSS reader handles files contained in the enclosure field of an RSS feed. With the increased use of RSS and podcasting, the security risks increase with it. Their is cause for concern, however proactive users and conscientious developers can easily subvert the risk by taking precautions seriously. Computer viruses and malware are cause for legitimate concern, there is ample time and action that can avert potential problems. About the Author: Sharon Housley manages marketing for FeedForAll http://www.feedforall.com software for creating, editing, publishing RSS feeds and podcasts. In addition Sharon manages marketing for FeedForDev http://www.feedfordev.com an RSS component for developers. RELATED ARTICLES & TUTORIALS
According to Technorati, there are over 15 million blogs as of July 2005. And during July, an average of 80,000 new blogs were created each day. If you own a blog, how are you going to promote it in order to stay ahead of the competition? Using RSS In Communication The following article includes pertinent information that may cause you to reconsider what you thought you understood. The most important thing is to study with an open mind and be willing to revise your understanding if necessary. The Future Of RSS Is Not Blogs Blogs vaulted RSS into the limelight but are unlikely to be the force that sustains RSS as a communication medium. The biggest opportunities for RSS are not in the blogosphere but as a corporate communication channel. RSS Makes Your Business Visible You may have noticed that many sites advertise the fact that they offer an RSS feed. Like many business owners, you probably wonder what RSS can do for your business. 6 Strong Reasons Why RSS Beats Email Marketing brand new marketing tool predicted to replace email is currently sweeping the World Wide Web like a storm. |
|
|
|
|
|
The views and opinions of authors expressed on Zeronese Webmaster Article Directory web sites do not necessarily state or reflect those of the Zeronese.net . |
|

