feeds as an attack vector?
At http://intertwingly.net/blog/2006/08/09/Attack-Delivery-TestSuite Sam Ruby writes: "It is just a matter of time. One of these days, some hacker will deface a popular site like Engadget. But instead of putting something visible on the site, they will put something invisible in the feed. By the magic of syndication, that data will then be distributed like spores to untold thousands of locations. In the process it will be transported from a relatively untrusted location (like BoingBoing) to a place of equal or greater trust. Places like popular portal sites, or just perhaps, to your very own hard drive. From there, it will lie in wait until you check for news. Invisibly it will spring into action. You won’t even notice it running. It will be able to do things that vary from uploading your preferences and passwords to a remote location, to downloading malware onto your machine. Shortly thereafter, this entry will be marked as read, or scroll off the bottom of your river of news, and you will never know how you just got p0wned." It seems like it would be worth thinking about this when working on any part of Drupal that aggregates or generates feeds. ..chris
This is important, since site would not suffer, and this can be undetected for some time. Meanwhile the attacker (or their "clients") have their links highly rated in search engines.
Op woensdag 9 augustus 2006 19:20, schreef Khalid B:
This is important, since site would not suffer, and this can be undetected for some time.
Meanwhile the attacker (or their "clients") have their links highly rated in search engines.
our feeds are passed trough filters. Any more fancy aggregator, such as node aggregator uses the normal input formatting. That includes the rel=nofollow, if you wish! Bèr -- PGP ber@webschuur.com http://www.webschuur.com/sites/webschuur.com/files/ber_webschuur.asc Layoutkeuze, de stap voordat je gaat (laten) ontwerpen.: http://help.sympal.nl/layoutkeuze_de_stap_voordat_je_gaat_laten_ontwerpen
participants (3)
-
Bèr Kessels -
Chris Johnson -
Khalid B