Top 10 winner
Hacking RSS Feeds
SPI Labs whitepaper on Feed Injection: RSS and Atom readers variously render feed markup literally, entity-decode it before display, or strip it, and the first two execute attacker script from title, link and description elements. Local readers that write HTML to disk and load it in IE grant local-zone ActiveX, giving file theft and unrestricted XMLHttpRequest port scanning.
Record
- Researcher
- Robert Auger
- Published by
- SPI Dynamics, Inc.
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Robert Auger, first published at the original source. Preserved copies are kept so the citation survives its host.