Read RSS, get hacked
Hackers have found a really simple solution to delivering malware
Computerworld - Users of Web feed services such as Real Simple Syndication (RSS) and Atom might want to make doubly sure they are not downloading malicious code along with their favorite Web content.
That's because the growing use of Web feed readers and the proliferation of content-aggregation sites are giving hackers a really simple way to deliver keystroke loggers, Trojan horses and other malware onto their computers, security analysts warn.
The feed-hacking threat is not particularly new. Howev—er, the severity of the problem could be rising as feed services begin moving into the mainstream, said Ray Dickenson, vice president of product management at Authentium Inc., a Palm Beach, Fla.-based security vendor. "Malware authors are just taking advantage of the interconnectedness of Web 2.0" to distribute their code more efficiently, he said.
Web feed services such as RSS allow Web content from multiple sources to be aggregated and automatically delivered to a desktop without requiring the user to actually visit any of the content-providing sites. Users simply subscribe to syndicated news and content feeds. Then, feed readers and content aggregators regularly check the feeds for updated content on the users' behalf -- and automatically push it out to the user when something new is found.
The security problem arises from the fact that many RSS- and Atom-based feed readers and aggregators simply pull in the content from the source without first checking to see whether it might contain malicious code, said Michael Sutton, security evangelist at SPI Dynamics Inc., an Atlanta-based Web application security vendor.
"It is like any other Web application security problem," Sutton said. "It all stems from the problem that user input is widely accepted without any validation. It's a huge problem. The server side and the client side are assuming that people are going to be inputting stuff the developer expected them to."
"Unfortunately, many of the applications that receive [feed] data do not consider the security implications of using content from third parties and unknowingly make themselves and their attached systems susceptible to various forms of attack," Robert Auger, formerly of SPI Dynamics, said in a white paper released last year.
As a result, the "potential for using Web-based feeds as an exploit deployment vector for both known and zero-day exploits is rather large," he said. The issue is amplified when a feed is resyndicated to other sites. "The potential exposed user base could be in the millions, making it an attractive method for worm deployment," Auger wrote.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Gartner Report: A Guide to Gartner's Enterprise Mobile Security Self-Assessment Gartner introduces a model and a Toolkit intended to help mobility and security IT leaders assess their enterprise mobility programs from a security...
- Gartner Report: Containing Mobile Security Risks With the 80/20 Rule IT planners can deliver better mobile protection with higher user satisfaction by segmenting users into risk groups before committing to specific management or...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts