Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-28-2006, 09:53 AM
rvincoletto@gmail.com
Guest
 
Posts: n/a
Default Blog readers are vulnerable to malicious codes

By Renata Vincoletto

Do you like to read a blog? Every day, before start to work, do you
read your favorite one? What do you use to be updated? RSS? Atom?

If yes, your computer could catch a virtual cold, says SPI Dynamics CTO
(http://www.techworld.com/Security/fe...eID=2745&email)
..

Software and services used to download feeds transmitted via the RSS or
Atom formats can download and execute JavaScript code buried within the
text.

And you are not safe, even if you use trustable services like
Bloglines, or readers like Firefox, because web feed could contain a
link to another Web site or blog that's hosting malicious JavaScript.
Or maybe a blog might have an area allowing readers to post public
comments. Those can also store malicious bits of JavaScript.

The best way to guard against these sorts of attacks would be for
blog-reading software and services to re-encode all JavaScript it
receives to render it harmless. Creating this filter would not cause
feeds to arrive much slower. But until as we know, no blog-reading
software or service re-encodes the JavaScript codes.

My comment: Take care! Don't forget to use a good anti-virus, firewall
and anti-spyware!

Read more: http://rvincoletto.multiply.com/journal/item/185


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 01:48 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45