Related Links

Featured Links





Recommended Products



 

 
Featured Articles

How to Find the Right Web Host and Avoid Costly Mistakes
One of the most important decisions you'll make as a Web site owner, Internet marketer or Webmaster, is choosing a reliable Web hosting service. Sorting through a multitude of hosting companies and making sense of the various service plans offered, can ...

Java Games For Your Cell Phone
Are you one of those people who get tired when standing in queue? Can't stop multitasking no matter what you do? Maybe you need to download some games for your cell phone. Java games are based on a very skinny programming language, and have surprisingly ...

Podcasting Tools
Podcasting is increasing in popularity and, realizing that many are interested in providing audio content in a podcast, we have assembled a collection of tools that make creation, promotion and listening to podcasts a little easier. 1.) Podcasting Tools - ...


Google
Rss Security
 


Security Implications Related to RSS.
As RSS gains momentum security fears loom large. As publishers are quickly finding innovative uses for RSS feeds, hackers are taking notice. The power and extendibility of RSS in its simplest form is also its achilles heel. The expansion capabilities of the RSS specification, specifically the "enclosure" field which has launched the podcasting phenomenon, is where the vulnerabilities lie. The enclosure field in itself is not the problem, in fact the majority of RSS feeds do not even use the enclosure tag. The enclosure tag is essentially used to link to file types, things like images, word documents, mp3 files, power point presentations, and executables and can be thought of in similar terms to email attachments.

The fact that RSS can be used to distribute these file types has opened a myriad of doors to users of the syndication standard, but also has created cause for concern. Most people do not feel that the risk is significant because people "choose" the content that they receive, and while it might make the distribution of malware, viruses and spy applications via RSS less prevalent, their is still the inherent risk of a infected file being distributed.

The problem is one of both technology and lack of education.
The danger lies in the fact that many RSS readers, news


aggregators, or pod-catchers automatically download the information contained in the enclosure field regardless of its file type or source.

Most RSS developers acknowledge the risks associated with the enclosure field, but few have had the forethought to include filtering, screening or authentication capabilities and many automatically download enclosures.

Nick Bradbury of Bradsoft/NewsGator seems to be proactive, designing FeedDemon with security in mind. FeedDemon uses an editable safelist of file types as well as allowing users to monitor what files are automatically downloaded. FeedDemon also contains hard-coded warnings related to specific file types.

Developers of ByteScout took a different approach to the handling of enclosure files, ByteScout does not automatically download anything without user intervention for each download.

Unfortunately, not all RSS readers, aggregators and podcatchers consider the possible security implications associated with RSS feeds and podcasts, some will automatically download enclosures without warning or any thoughts of security. Be sure to examine how your RSS reader handles files contained in the enclosure field of an RSS feed.

With the increased use of RSS and podcasting, the security risks increase with it. Their is cause for concern, however proactive users and conscientious developers can easily subvert the risk by taking precautions seriously. Computer viruses and malware are cause for legitimate concern, there is ample time and action that can avert potential problems.


About the Author
Sharon Housley manages marketing for FeedForAll http://www.feedforall.com software for creating, editing, publishing RSS feeds and podcasts. In addition Sharon manages marketing for FeedForDev
Sign up for PayPal and start accepting credit card payments instantly.
News



Jill on Money: Real estate, munis, life insurance
CBS News
Download the podcast on iTunes Download the podcast on feedburner Download this week's show (MP3) The Facebook IPO hype morphed into a fiasco throughout the week, diverting attention away from more pressing issues. To understand the issues surrounding ...

and more »

MP3 Toolkit
PCWorld (blog)
MP3 Toolkit is simple and it works, letting you convert audio files to a number of different types, merge multiple files into one, clip files for ringtones or the like, edit tags, rip files from CD, and record using a microphone.

and more »

MP3 ROUNDUP: Savages, Indian Wells, How To Dress Well, The Child of Lov ...
ChartAttack
by CHARTattack Primal aggression and intensity, London four-piece Savages' caustic post-punk is musically and emotionally raw. They've been tearing it up for months with live shows, but they have a 7” on the way, and below is the fantastic B-side ...


Ghacks Technology News

MP3 Toolkit offers all the MP3 Tools you will ever need
Ghacks Technology News
When it comes to mp3 files, you sometimes may need a set of tools to edit, convert or even rip them in first place. While you can use specialized tools for that which provide you with some of the functionality that you may need, a set of tools that Mp3 ...


Creating a Custom iTunes Audiobook From Multiple MP3s
About - News & Issues
Rather than wasting time (and possibly money) on third-party software, you might find that the facility in iTunes to combine multiple MP3 files into one audiobook could be the perfect solution. Using this often overlooked feature enables you to create ...

and more »