Search the web
Sign In
New User? Sign Up
rss-public
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Blog feeds may carry security risk   Message List  
Reply | Forward Message #743 of 1975 |
http://news.zdnet.com/2100-1009_22-6102171.html?tag=nl.e589

OK, this seems a little naive. Javascript in RSS shouldn't create any
more vulnerabilities than Javascript in HTML. Anybody know differently?

more thoughts
http://www.kbcafe.com/spam/?guid=20060808140302

Randy Charles Morin
http://www.kbcafe.com/rss






Tue Aug 8, 2006 9:10 pm

randymorin
Offline Offline
Send Email Send Email

Forward
Message #743 of 1975 |
Expand Messages Author Sort by Date

http://news.zdnet.com/2100-1009_22-6102171.html?tag=nl.e589 OK, this seems a little naive. Javascript in RSS shouldn't create any more vulnerabilities than...
Randy Morin
randymorin
Offline Send Email
Aug 8, 2006
9:11 pm

... The threat is very real, companies like Bloglines, NewsGator, and Microsoft are treating it very seriously, and the whitepaper describing the exploits...
Sam Ruby
sa3ruby
Offline Send Email
Aug 8, 2006
9:26 pm

If it is of any help to the community, I have created several test feeds to do some experimenting. http://rsstest.markwoodman.com/ Trying these out, I have...
Mark Woodman
mark.woodman
Offline Send Email
Aug 8, 2006
10:51 pm

... Oh, for instance, Bloglines keeps pretty much their entire interface in JavaScript, so once you've got script injection you can (or could, last time I...
Phil Ringnalda
philringnalda
Offline Send Email
Aug 8, 2006
11:12 pm

... For a desktop client (at least Windows clients using IE for the renderer) the javascript is by default running in a different security zone than it would...
James Holderness
james_holder...
Offline Send Email
Aug 8, 2006
11:30 pm

... What's to understand? Just kill any javascript that might be present inside anything being displayed. Why would any feed tool do otherwise?...
Bill Kearney
wkearney99
Offline Send Email
Aug 9, 2006
1:15 am

... present inside ... That was my reaction too. So, I finally got around to writing some dead-simple test RSS feeds... and completely whacked my online...
Mark Woodman
mark.woodman
Offline Send Email
Aug 9, 2006
1:24 am

... First, many consumers do the equivalent of strcpy of the bytes inside the description without doing the equivalent of full tag soup HTML parser. BTW,...
Sam Ruby
sa3ruby
Offline Send Email
Aug 9, 2006
9:23 am

... Any effort at the syntactic level by non-browser libraries is destined to become a game of whack-a-mole. Browser vendors should have dealt with this one a...
robertsayre2000
Offline Send Email
Aug 13, 2006
1:57 am

... First, many consumers do the equivalent of strcpy of the bytes inside the description without doing the equivalent of full tag soup HTML parser. BTW,...
Sam Ruby
sa3ruby
Offline Send Email
Aug 10, 2006
11:44 am

... I've been through that too, but you should be able to unsubscribe yourself with a bit of effort. You just need to know the URL required to unsubscribe from...
James Holderness
james_holder...
Offline Send Email
Aug 9, 2006
2:53 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help