Read RSS, get hacked
Hackers have found a really simple solution to delivering malware
Computerworld - Users of Web feed services such as Real Simple Syndication (RSS) and Atom might want to make doubly sure they are not downloading malicious code along with their favorite Web content.
That's because the growing use of Web feed readers and the proliferation of content-aggregation sites are giving hackers a really simple way to deliver keystroke loggers, Trojan horses and other malware onto their computers, security analysts warn.
The feed-hacking threat is not particularly new. Howev—er, the severity of the problem could be rising as feed services begin moving into the mainstream, said Ray Dickenson, vice president of product management at Authentium Inc., a Palm Beach, Fla.-based security vendor. "Malware authors are just taking advantage of the interconnectedness of Web 2.0" to distribute their code more efficiently, he said.
Web feed services such as RSS allow Web content from multiple sources to be aggregated and automatically delivered to a desktop without requiring the user to actually visit any of the content-providing sites. Users simply subscribe to syndicated news and content feeds. Then, feed readers and content aggregators regularly check the feeds for updated content on the users' behalf -- and automatically push it out to the user when something new is found.
The security problem arises from the fact that many RSS- and Atom-based feed readers and aggregators simply pull in the content from the source without first checking to see whether it might contain malicious code, said Michael Sutton, security evangelist at SPI Dynamics Inc., an Atlanta-based Web application security vendor.
"It is like any other Web application security problem," Sutton said. "It all stems from the problem that user input is widely accepted without any validation. It's a huge problem. The server side and the client side are assuming that people are going to be inputting stuff the developer expected them to."
"Unfortunately, many of the applications that receive [feed] data do not consider the security implications of using content from third parties and unknowingly make themselves and their attached systems susceptible to various forms of attack," Robert Auger, formerly of SPI Dynamics, said in a white paper released last year.
As a result, the "potential for using Web-based feeds as an exploit deployment vector for both known and zero-day exploits is rather large," he said. The issue is amplified when a feed is resyndicated to other sites. "The potential exposed user base could be in the millions, making it an attractive method for worm deployment," Auger wrote.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts