The problem doesn't affect only blogs--any kind of information feed using any kind of format could potentially be used to transmit malicious content to a subscriber, Auger said. People, for example, subscribe to mailing lists and news Web sites via RSS, he said, noting "this is about the entire concept of Web feeds."
SPI Dynamics examined a number of online and offline applications used to read RSS and Atom feeds. In many cases, any JavaScript code delivered on the feed would run on the user's PC, meaning it could be vulnerable to attack, Auger said. JavaScript is a scripting language that experts say is increasingly causing security concerns.
Attackers could exploit the problem by setting up a malicious blog and enticing a user to subscribe to the RSS feed. More likely, however, they would add malicious JavaScript to the comments on a trusted blog, Auger said. "A lot of blogs will take user comments and stick them into their own RSS feeds," he said.
Also, attackers could send malicious code to mailing lists that offer RSS or Atom feeds and commandeer vulnerable systems that way, Auger said. Feeds are popular because they let people consolidate information streams from multiple sites, such as blogs, in one application, called a feed reader, removing the need to surf to multiple sites.
Many of the popular feed reading applications are faulted because the designers have failed to add valuable security checks, Auger said. In particular, the applications should not allow JavaScript that is included in feeds to run. Instead, it should be filtered out, he said.
Additionally, some reader software on Windows systems uses Internet Explorer to display feed content, but doesn't use basic security settings that isolate the content. Instead, the JavaScript is downloaded to the PC and has full access, which can fully expose a person's PC, Auger said.
"A large percentage of the readers I tested had some kind of an issue," he said. In his presentation, Auger listed Bloglines, RSS Reader, RSS Owl, Feed Demon, and Sharp Reader as vulnerable.
As protection, people could switch to a nonvulnerable reader. Also, feed publishers could ensure that their feeds don't include malicious JavaScript or any script at all, Auger said. Some services, however, rely on JavaScript to deliver ads in feeds, he noted.
Blogs or other online forums are very effective in linking basic consumers to the technology world, so if some issue arise with security, that link could be broken. These RSS issues are related to the increased amount of "splog" all over blogs these days.
We should begin developing ways to get rid of this splog like we have with the rediculous amounts of spam that are sent to us. If your everyday consumers can not safely communicate with blogs, then the separation between the two increases and many more issues arise within the technology world. <a class="jive-link-external" href="http://www.techknowbizzle.com/2006/07/spam-spim-splog-on-rise.html" target="_newWindow">http://www.techknowbizzle.com/2006/07/spam-spim-splog-on-rise.html</a>
The company says that manufacturing facilities in Shenzhen and Chengdu, China, will be inspected by a group "dedicated to ending sweatshop conditions in factories worldwide."
A group calling itself Evil Shadow Team reportedly hacked into Microsoft's online store in India, stealing usernames and passwords of the site's customers.
The Samsung Galaxy Mini 2 S6500 could make its debut at the Mobile World Congress in Barcelona later this month, according to a leaked promotional image.
The space agency powers down its last System Z machine, years after IBM stopped selling them for the mathematical calculation jobs for which NASA originally bought them.
We should begin developing ways to get rid of this splog like we have with the rediculous amounts of spam that are sent to us. If your everyday consumers can not safely communicate with blogs, then the separation between the two increases and many more issues arise within the technology world.
<a class="jive-link-external" href="http://www.techknowbizzle.com/2006/07/spam-spim-splog-on-rise.html" target="_newWindow">http://www.techknowbizzle.com/2006/07/spam-spim-splog-on-rise.html</a>