MS, RSS and hack attacks
p2pnet.net News:- Microsoft’s decision to support RSS in Longhorn and IE7 generated a lot of attention and speculation.
But what about security? – asks Netcraft.
"Integrating RSS into the operating system will likely have hackers contemplating new scenarios,” it says, going on:
“RSS is currently consumed through a wide variety of news readers, email clients, web sites and browsers. As RSS becomes a standard feature in IE7 and Longhorn, it may become more attractive to malware authors with an interest in delivering malicious code from the Internet onto RSS-enabled desktops.
“RSS is an XML format that is widely used to syndicate news from weblogs or news sites. RSS can include HTML tags and many types of content, such as the audio files included in ‘podcasting’ feeds, the current rage among bloggers.”
But the format’s very versatility could allow malicious content to be included in feeds and executed by newsreaders or browsers, says Netcraft, adding:
“The possible use of RSS to deliver malware and spam was highlighted by Mark Pilgrim in 2003 …
Something you think we should know? tips[at]p2pnet.net
See:-
attention and speculation – Longhorn to have RSS support, p2pnet, June 24, 2005
Netcraft – The Missing Ingredient in Buzz About RSS, June 25, 2005




