MarketingStudies.net logo    
spacer Marketing views, news and experience with the difference Logo Logo
Subscribe to the RSS Marketing e-zine

Providing strategic semi-monthly views on best RSS uses and practices and latest RSS news. [privacy]

Email Address:
RSS Content Feed What is this?
spacer
The Marketing Diary   l   The RSS Diary   l   RSS Marketing   l   RSS Cases Blog    l   Interactive Optimization Blog


Get the free crash-course in RSS marketing, to find out exactly how you'll profit from implementing this new technology.

Covers everything from RSS for direct marketing to using RSS for SEO.

Complete the form below to receive your free report now!

Your name:

Your e-Mail:

The RSS Cases Blog
The RSS Cases Blog brings you RSS technology advice, helps you understand RSS technology issues and explains different RSS business cases.

[June 14, 2007]
Using RSS Radars to Find Domains for SEO/SEM

[April 4, 2007]
The History and Future of RSS?

[March 26, 2007]
Yahoo Pipes Regex Module

[March 26, 2007]
RSS Cases - Mon Mar 26, 2007

[March 22, 2007]
Teqlo Web Feed and Application Mashup Tool

You are here: Home » The RSS Marketing Diary » RSS for Webmasters » Sharon Housely on RSS Security

October 4, 2005

Sharon Housely on RSS Security

My friend Sharon Housely just made a great article on RSS and security available for re-publication. It follows in full ...

Security And RSS
by Sharon Housely

RSS is growing at a lightening speed. What was once only known as a "techie tool", RSS is becoming a tool that is continuously being used by the general population.

Along with the good comes, the not so good. And while some have mentioned the emergence of RSS spam, where content publishers dynamically generate nonsensical feeds stuffed with keywords, the real concern relates to security. While an annoyance to the search engines, spam in RSS feeds pales in comparison to the possible security concerns that could be in RSS' future.

Security Implications Related to RSS
As RSS gains momentum security fears loom large. As publishers are quickly finding innovative uses for RSS feeds, hackers are taking notice. The power and extendibility of RSS in its simplest form is also its achilles heel. The expansion capabilities of the RSS specification, specifically the "enclosure" field which has launched the podcasting phenomenon, is where the vulnerabilities lie.

The enclosure field in itself is not the problem, in fact the majority of RSS feeds do not even use the enclosure tag. The enclosure tag is essentially used to link to file types, things like images, word documents, mp3 files, power point presentations, and executables and can be thought of in similar terms to email attachments.

The fact that RSS can be used to distribute these file types has opened a myriad of doors to users of the syndication standard, but also has created cause for concern.

Most people do not feel that the risk is significant because people "choose" the content that they receive, and while it might make the distribution of malware, viruses and spy applications via RSS less prevalent, their is still the inherent risk of a infected file being distributed.

The problem is one of both technology and lack of education
The danger lies in the fact that many RSS readers, news aggregators, or pod-catchers automatically download the information contained in the enclosure field regardless of its file type or source.

Most RSS developers acknowledge the risks associated with the enclosure field, but few have had the forethought to include filtering, screening or authentication capabilities and many automatically download enclosures.

Nick Bradbury of Bradsoft/NewsGator seems to be proactive, designing FeedDemon with security in mind. FeedDemon uses an editable safelist of file types as well as allowing users to monitor what files are automatically downloaded. FeedDemon also contains hard-coded warnings related to specific file types.

Developers of ByteScout took a different approach to the handling of enclosure files, ByteScout does not automatically download anything without user intervention for each download.

Unfortunately, not all RSS readers, aggregators and podcatchers consider the possible security implications associated with RSS feeds and podcasts, some will automatically download enclosures without warning or any thoughts of security. Be sure to examine how your RSS reader handles files contained in the enclosure field of an RSS feed.

With the increased use of RSS and podcasting, the security risks increase with it. Their is cause for concern, however proactive users and conscientious developers can easily subvert the risk by taking precautions seriously. Computer viruses and malware are cause for legitimate concern, there is ample time and action that can avert potential problems.

Sharon Housley manages marketing for FeedForAll http://www.feedforall.com software for creating, editing, publishing RSS feeds and podcasts. In addition Sharon manages marketing for FeedForDev http://www.feedfordev.com an RSS component for developers.

Comments

xcvxcvxcv

Posted by: xxvx at December 6, 2005 1:53 PM

ads 2007-07-24 Convert your favorite vinyl albums to MP3 s with the Ion iTTUB turntable W

Posted by: ads 2007-07-24 Convert your favorite vinyl albums to MP3 s with the Ion iTTUB turntable W at September 15, 2007 12:05 AM

ow, too bad...this wasn't available when I began my LP to CD conversion process. I have s

Posted by: ow, too bad...this wasn't available when I began my LP to CD conversion process. I have s at September 15, 2007 12:07 AM
Post a comment


*


*





2 + 2 =
Remember personal info?






Related Articles

[April 18, 2006]
Media RSS Now Supported by Gecko Tribe

[January 23, 2006]
More on RSS and Copyright Issues: Still No Solution

[January 5, 2006]
Popular RSS Extensions in One Place

[August 11, 2005]
FeedDigest: An Excellent RSS Radar or NewMastering Tool

[August 9, 2005]
Google News via RSS

[August 8, 2005]
How to Make RSS Feeds Work in IE7 and Windows Vista?

[August 8, 2005]
Easily Publish Syndicated Content or Syndicate Your Own

[July 25, 2005]
An RSS Web Developer Resource Index

[July 19, 2005]
Displaying RSS Feeds on Your Site

[July 19, 2005]
The 'Atom 1.0 vs RSS 2.0' Wiki

Recent Articles in iNet Marketing Article Database
Recent Articles

Introduction to Strategic Marketing Pillars

Marketing as an Integrated Communicational Process

The Marketing Strategy as the Essential Element

One-on-One Sales as the First Step

Constant Change

Unique Pre-Dispositions