Article: RSS Security

iSnare.com - Free Content Articles Directory
Authors Contents [Advanced Search][Add OpenSearch][Job Search]
Distribute your articles to thousands of article sites for only $2 and below! Read more...

Index  Internet
 

RSS Security

 
[ Contact the Author] [ Send to a Friend] [ Article Publisher] [Make PDF] [ Print] [ Bookmark & Share]
 
Read our Terms of Service before reprinting this article. The submitter specified above has claimed the rights to this article.
S. Housley

RSS is growing at a lightening speed. What was once only known as a "techie tool", RSS is becoming a tool that is continuously being used by the general population. Along with the good comes, the not so good. And while some have mentioned the emergence of RSS spam, where content publishers dynamically generate nonsensical feeds stuffed with keywords, the real concern relates to security. While an annoyance to the search engines, spam in RSS feeds pales in comparison to the possible security concerns that could be in RSS' future.

Security Implications Related to RSS.

As RSS gains momentum security fears loom large. As publishers are quickly finding innovative uses for RSS feeds, hackers are taking notice. The power and extendibility of RSS in its simplest form is also its achilles heel. The expansion capabilities of the RSS specification, specifically the "enclosure" field which has launched the podcasting phenomenon, is where the vulnerabilities lie. The enclosure field in itself is not the problem, in fact the majority of RSS feeds do not even use the enclosure tag. The enclosure tag is essentially used to link to file types, things like images, word documents, mp3 files, power point presentations, and executables and can be thought of in similar terms to email attachments.

The fact that RSS can be used to distribute these file types has opened a myriad of doors to users of the syndication standard, but also has created cause for concern.

Most people do not feel that the risk is significant because people "choose" the content that they receive, and while it might make the distribution of malware, viruses and spy applications via RSS less prevalent, their is still the inherent risk of a infected file being distributed.

The problem is one of both technology and lack of education.

The danger lies in the fact that many RSS readers, news aggregators, or pod-catchers automatically download the information contained in the enclosure field regardless of its file type or source.

Most RSS developers acknowledge the risks associated with the enclosure field, but few have had the forethought to include filtering, screening or authentication capabilities and many automatically download enclosures.

Nick Bradbury of Bradsoft/NewsGator seems to be proactive, designing FeedDemon with security in mind. FeedDemon uses an editable safelist of file types as well as allowing users to monitor what files are automatically downloaded. FeedDemon also contains hard-coded warnings related to specific file types.

Developers of ByteScout took a different approach to the handling of enclosure files, ByteScout does not automatically download anything without user intervention for each download.

Unfortunately, not all RSS readers, aggregators and podcatchers consider the possible security implications associated with RSS feeds and podcasts, some will automatically download enclosures without warning or any thoughts of security. Be sure to examine how your RSS reader handles files contained in the enclosure field of an RSS feed.

With the increased use of RSS and podcasting, the security risks increase with it. Their is cause for concern, however proactive users and conscientious developers can easily subvert the risk by taking precautions seriously. Computer viruses and malware are cause for legitimate concern, there is ample time and action that can avert potential problems.

Important NoticeDISCLAIMER: All information, content, and data in this article are sole opinions and/or findings of the individual user or organization that registered and submitted this article at Isnare.com without any fee. The article is strictly for educational or entertainment purposes only and should not be used in any way, implemented or applied without consultation from a professional. We at Isnare.com do not, in anyway, contribute or include our own findings, facts and opinions in any articles presented in this site. Publishing this article does not constitute Isnare.com's support or sponsorship for this article. Isnare.com is an article publishing service. Please read our Terms of Service for more information.

Sharon Housley manages marketing for FeedForAll http://www.feedforall.com software for creating, editing, publishing RSS feeds and podcasts. In addition Sharon manages marketing for FeedForDev http://www.feedfordev.com an RSS component for developers.
Article Tags: rss [See Dictionary], enclosure [See Dictionary], security [See Dictionary]
Got a question about this article? Ask the community!
Article published on September 22, 2005 at Isnare.com
 
Rate this article:

How Do You Overcome Google's Filters
Submitted by: S. Housley

Google tends to not rank new domains In an effort to deter spammers from generating new websites, Google has implemented filters for new websites, which means that it can be a challenge for a new website to rank in Google's organic search results until they are deemed trustworthy...

What Rss Is Not!
Submitted by: S. Housley

It is difficult to have a conversation about technology these days that does not involve RSS In the age of the Internet, communication is expected to be instantaneous...

How To Get Ideas For Rss Feeds And Blog Posts
Submitted by: S. Housley

The best blogs and feeds are those that contain unique, fresh, compelling, content So where do these prolific posters get their ideas...

Webmaster And Small Business Resolutions
Submitted by: S. Housley

New Years Resolutions Each and every year people around the world mark the first day of the New Year with resolutions...

RSS Feed And Blog Etiquette
Submitted by: S. Housley

Citizen journalists and writers have become common place on the web Perhaps you are considering blogging, but are unsure of how to enter the world of online journaling...

Blogging Is A Dangerous Game
Submitted by: S. Housley

I have heard many a blogger say that blogging fills a need While blogging provides a humanizing effect on news and journaling, it also opens a window into personal lives...

The Dangers Of The Anonymous Internet
Submitted by: S. Housley

Attempting to legislate the Internet will not work, as the Internet is global and covers areas where no single government's rule applies...

The Question Of Online Credibility
Submitted by: S. Housley

Credibility online is becoming more and more of an issue Anyone can have a blog or post to a forum and anyone can edit wiki entries...

Everything You Need To Know About Linking
Submitted by: S. Housley

Websites that are able to amass a large number of links from related websites that contain relevant content, tend to have an advantage when attempting to rank well in the large search engines...

Online Safety Concerns
Submitted by: S. Housley

The proliferation of computer technology and emergence of the Internet has enhanced the lives of children and adults...

Selecting An RSS Reader Or News Aggregator
Submitted by: S. Housley

Reading RSS Feeds While many have resisted the urge to decipher the meaning behind the acronym RSS, the vast majority of technically knowledgeable online surfers have begun incorporating RSS into their daily routines...

Tips For Search Engine Optimization
Submitted by: S. Housley

Not only do you have just a few seconds to grab the attention of the web visitor, content developers must perform well within search engine searches so they are "found"when web surfers search on related keywords or phrases...

Is Google Really Big Brother?
Submitted by: S. Housley

Anti-Google sentiment is on the rise Web pundits have tossed around monopoly theories and privacy advocates have warned of a day of reckoning...

Interesting RSS Feeds More Than Just News
Submitted by: S. Housley

The core use for RSS is generally considered news headlines and blog syndication, but innovative businesses are learning to use RSS in different ways...

Making Money From RSS Feeds
Submitted by: S. Housley

Publishers are evaluating options and determining how they can profit from RSS feeds The two obvious contenders that publishers are considering using to profit from their RSS feeds are: subscription RSS feeds and RSS feed advertisements...

Make Extra Money Online
Submitted by: Blanca Ciotoiu

If you are expecting that I'm going to tell you a fast way to make extra money online then, you are wrong...

Web Site Design and Development – Tell a Story to Build Your Credibility and Educate Customers
Submitted by: Daljeet Sidhu

The best way to attract customers to your business is to make them understand what sets you apart from the competition...

Traffic Builder For Free
Submitted by: Dansar Gin

After you decide to have a website and to buy a domain name for your website you will ask a lot of questions like: - What is the right way to start...

What Are Meta Tags and Why Are They Important?
Submitted by: Blake Evans

A “meta tag” is a common phrase that new web designers generally have to deal with as soon as they sit down to create a website...

Podcasting
Submitted by: John Taylor

A podcast is a succession of digital media files, audio or video, that are discharged digressively and downloaded through web syndication...

Bang For Buck – How to Best Apply Twitter to Your Business and Earn Money Online
Submitted by: Trond Lyngbø

The digital world is growing and changing at an explosive rate As always, change brings both business opportunities and threats...

The Role of Backlinks in the Success of a Website
Submitted by: Kanaga Siva

The goal of most webmasters today is to obtain as many backlinks as possible for their websites by virtue of the fact that these links bestow enormous benefits on their websites...

SEO – Do You Know The Top 7 Traits Of Legitimate Search Engine Optimization Companies
Submitted by: Daljeet Sidhu

Did you know that nine out of ten people access online information through a search engine (SE) And eight out ten do not go past the first page of the search results...

Profitable Internet Ventures: Starting Up
Submitted by: Alan Tolchin

The beginning internet marketer faces fierce competition especially in the category of affiliate marketing...

Fast Link Building Techniques
Submitted by: Alexander Faust

When you are working on a website’s search engine optimization, link building probably is the most important task you need to do...

Make Money From Google Adsense
Submitted by: Stephen Ng

Learning how to make money from Google Adsense is probably the easiest way to make money online It is made possible when Internet giant Google began their Adsense service in March 2003 and quickly became the biggest force in online advertising...

How to Make a Money Tree
Submitted by: Stephen Ng

Before I discuss on how to make a money tree, it is important to touch on why many people are sceptical and always wondered on the subject can you make money online...

How CloudBerry Online Backup Works
Submitted by: Jason Kay

CloudBerry online Backup is designed to leverage Amazon S3 Storage and provide a powerful backup and restore system that is there if you need it...

Finding High Quality Links to Promote Your Website
Submitted by: Jason Kay

One of the best ways to promote your website is by finding high quality links This type of site promotion is known as link popularity...

What is Local Search SEO?
Submitted by: Stephen Logan

Well, the easy answer for this is that Local Search is a facet of search engine optimisation (SEO), which specifically targets your geographic locality...

Isnare.com Footer Divider

© 2004-2009. Isnare Free Articles - An Isnare Online Technologies Free Articles Project. All Rights Reserved.   Privacy Policy