CNet reports on a BlackHat talk that brought up security issues with some aggregators:
Also, attackers could send malicious code to mailing lists that offer RSS or Atom feeds and commandeer vulnerable systems that way, Auger said. Feeds are popular because they let people consolidate information streams from multiple sites, such as blogs, in one application, called a feed reader, removing the need to surf to multiple sites.
In other news:
Many of the popular feed reading applications are faulted because the designers have failed to add valuable security checks, Auger said. In particular, the applications should not allow JavaScript that is included in feeds to run. Instead, it should be filtered out, he said.
BottomFeeder ignores Javascript (it can't do otherwise) - which makes it safe from this sort of thing
Technorati Tags:
rss, atom, syndication, security