RSS Feeds at Risk From Attackers?

By Ed Oswald | Published August 4, 2006, 2:05 PM

Likely thought by many to be harmless, security researchers are now warning that RSS feeds can be used to launch attacks against unprotected computers. Hackers could insert malicious JavaScript in the feeds, which in turn would be delivered to the user.

The comments were made during a presentation at the Black Hat convention in Las Vegas, a yearly meeting of both hackers and security researchers. SPI Dynamics Security Engineer Robert Auger said that the issue could potentially affect any such information feed.

Auger's company said any type of RSS reader was susceptible to attacks, whether it be software or web-based. Information at risk could include potentially sensitive information, including passwords and personal data.

Especially disconcerting is the fact that attacks could be launched from trusted sites. Some blogs now include comments to Web posts within the feed, and all an attacker would have to do is include the JavaScript code within that comment for it to be distributed.

While attackers could launch their own blogs and feeds to distribute the harmful code, Auger believes that the previously mentioned scenario is likely to be the most commonly used method.

But who is to blame for the security risk? It appears to be the creators of the RSS applications themselves, who have failed to include proper security checks within the programs.

Of the Web-based readers, Bloglines was mentioned as vulnerable to attack. Of the software readers, Auger mentioned RSS Reader, RSS Owl, Feed Demon, and Sharp Reader. It should be mentioned this list of vulnerable readers is by no means complete; Auger was still contacting vendors about the problem at the time of his presentation.

To protect computers, Auger has advised that users go into their options and disable scripts, applets, and plug-ins from being launched within feeds. "Wherever you get data from you can't assume that data is good," he told the audience.

Comments

Here's something I learnt ages ago--- NOTHING IS SAFE.
"But who is to blame for the security risk? It appears to be the creators of the RSS applications themselves, who have failed to include proper security checks within the programs." Okay, so you blame everybody except yourself.

Computer's are vulnerable to attacks, let's blame Charles Babbage for inventing the computer. Windows has security holes. Let's blame Microsoft for giving us a more useful interface. Yahoo has the highest no. of bot users that spam. Let's shut Yahoo down. Blaming anyone can't help you, Auger. Instead of friggin' blaming, do the world some good and either create security patches for RSS readers or shoot yourself.

Score: 0

|

> Likely thought by many to be harmless

By who? Every professional coder on this planet knows that you don't trust data from outside sources. Do you really think people aren't validating RSS feeds that they are integrating into their site?

If Robert Auger received money from you and others for this "revelation" then he just pulled off a hilarious con.

However next time get a coder to look over the story and laugh in your face before you publish time wasting dribble.

It's like this, you don't leave a gun out on a table in a public area. He has taken the attitude that this is because a child could pick it up and shoot somebody, but now he alerting you to the "hidden danger" that adults too can pick up that gun and shoot people with it. Well thanks Einstein!

Score: 0

|

try sage in firefox

Score: 0

|

Somehow I doubt Firefox's Live Bookmarks are vulnerable.

Score: 0

|

Something I've leant over the past couple of years... nothing is invulnerable.

and Firefox's RSS reading tech would bhe similar to Opera or IEs, would it not? I mean, how many diff types of RSS is there?

"But who is to blame for the security risk? It appears to be the creators of the RSS applications themselves, who have failed to include proper security checks within the programs."

Wouldn't RSS exclude Javascript anyway?

Score: 0

|

Hmmmmmmmm! How many of you said I was retarded or stupid for telling you that this was 100% going to happen??????? PC_Tools you were the first one.

Score: 0

|

Well, if it isn't for one thing, I'm sure it's another. ;)

(And if yer gonna attribute something to me, at least link to it)

Score: 0

|

I don't really feel like digging in the trash to find a little note.

Score: 0

|

I have yet to write you a note.

Unless you're name is Eric... In which case, what the hell are you still doing here? It was pink..and it said, "You're Fired." ;)

Score: 0

|

Any word on which readers are NOT vulnerable?

Score: 0

|

asinine

Score: 0

|

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Report: Evidence of further creativity with Windows 7 upgrade prices

A ZDNet blogger did some serious digging for clues as to a reported price break on multiple Windows 7 Home Premium licenses, and may have found it.