MarketingStudies.net logo    
spacer Marketing views, news and experience with the difference Logo Logo
Subscribe to the RSS Marketing e-zine

Providing strategic semi-monthly views on best RSS uses and practices and latest RSS news. [privacy]

Email Address:
RSS Content Feed What is this?
spacer
The Marketing Diary   l   The RSS Diary   l   RSS Marketing   l   RSS Cases Blog    l   Interactive Optimization Blog


Get the free crash-course in RSS marketing, to find out exactly how you'll profit from implementing this new technology.

Covers everything from RSS for direct marketing to using RSS for SEO.

Complete the form below to receive your free report now!

Your name:

Your e-Mail:

The RSS Cases Blog
The RSS Cases Blog brings you RSS technology advice, helps you understand RSS technology issues and explains different RSS business cases.

[August 14, 2006]
Roll Your Own RSS Feed Reader

[August 13, 2006]
Will Atom Power The Future Web?

[July 6, 2006]
Sabifoo - A New Way To Podcast?

[June 26, 2006]
Web Feed + Podcasting Notes #8 - Do You Delete RSS Feeds?

[June 24, 2006]
Getting Wider Adoption For RSS

You are here: Home » The RSS Marketing Diary » RSS for Webmasters » RSS Security Issues

June 6, 2005

RSS Security Issues

It's quite evident that RSS enclosures are a security threat, especially if RSS aggregator developers don't start automatically (by default) blocking certain types of content item "attachements". If they don't, RSS could easily be used to "infest" trusting people with harmful executable files.

Furthermore, in an IT Manager's Journal article, Richard Stiennon, vice president of threat research at anti-spyware company Webroot, warns against the possibility of profit seekers going further and finding new and new ways of exploiting RSS.

Malicious code in full-text content items is the first that comes to mind.

Comments

It is too bad the dark side of the internet will eventually exploit RSS.

The first security problem I see is the embedded email address of the publisher in the RSS (XML) code.

A feed will not validate without an email address in the proper format and it is only a matter of time before spammers start harvesting email addresses from feeds.

Posted by: Chris Lang at July 18, 2005 3:57 PM
Post a comment


*


*





2 + 2 =
Remember personal info?






Related Articles

[April 18, 2006]
Media RSS Now Supported by Gecko Tribe

[January 23, 2006]
More on RSS and Copyright Issues: Still No Solution

[January 5, 2006]
Popular RSS Extensions in One Place

[October 4, 2005]
Sharon Housely on RSS Security

[August 11, 2005]
FeedDigest: An Excellent RSS Radar or NewMastering Tool

[August 9, 2005]
Google News via RSS

[August 8, 2005]
How to Make RSS Feeds Work in IE7 and Windows Vista?

[August 8, 2005]
Easily Publish Syndicated Content or Syndicate Your Own

[July 25, 2005]
An RSS Web Developer Resource Index

[July 19, 2005]
Displaying RSS Feeds on Your Site

Recent Articles in iNet Marketing Article Database
Recent Articles

Introduction to Strategic Marketing Pillars

Marketing as an Integrated Communicational Process

The Marketing Strategy as the Essential Element

One-on-One Sales as the First Step

Constant Change

Unique Pre-Dispositions