Language Selection

English French German Italian Portuguese Spanish

RSS, Spyware’s next frontier.

Filed under
Security

Richard Stiennon VP of Threat Research at anti-Spyware company Webroot Software, Inc earlier this year announced his predictions for 2005 in relation to security vulnerabilities and Spyware problems. Most of the predictions were fairly predictable like:

The number of new Microsoft vulnerabilities will grow.

Which isn’t a surprise to anyone in the IT industry and probably a good many people that aren’t. Other predictions like: The US and European nations will pass anti-spyware laws, and the number of different types of spyware will double to 3,000 are not exactly unexpected either.

However at least one of the predictions causes a pause for further thought. In short one prediction that RSS syndication will soon be used as a tool to distribute advertising, Spyware and other malicious code. RSS is basically just XML so the medium isn’t potentially dangerous by itself, but flaws that target specific RSS readers could conceivably result in the transfer of Spyware. RSS is already being used to distribute advertising so that one isn’t a surprise either. RSS has most of the benefits of E-mail and that means it also has most of the problems. One of those problems is that malicious parties can use social engineering tricks to get people to follow links in RSS to download malicious content, which is probably what Mr Stiennon meant. The problem with that theory is that a user must first subscribe to an RSS feed to be at risk at all, which makes it considerably less reliable a method of transferring malicious content then E-mail or web pages.

One other prediction Mr Stiennon made was that Firefox would become the target of Spyware sometime in the first half of this year. I’m not so sure about this one because it is mostly the more techie users that have become hooked on Firefox and they would not be particularly good targets for Spyware since they are also the kind of users most likely to have anti-Virus and anti-Spyware software running, if they are using Windows that is.

Source.

More in Tux Machines

Canonical Patches Four Linux Kernel Vulnerabilities in Ubuntu 15.04 and Ubuntu 14.04

Today, July 28, Canonical published details about new Linux kernel updates for its Ubuntu 15.04 (Vivid Vervet) and Ubuntu 14.04 LTS (Trusty Tahr) operating systems, urging users to update the installations as soon as possible. Read more

Ubuntu Software Center Is Really Hated by the Community, but Why?

Ubuntu MATE recently decided to drop the Ubuntu Software Center and it will not longer be available with the upcoming 15.10 Alpha 2 release. This is interesting in itself, but this editorial is about another aspect. From the looks of it, a very large part of the Ubuntu and Linux community really hates the Ubuntu Software Center. Read more

Wine Announcement

The Wine development release 1.7.48 is now available. What's new in this release (see below for details): - Fleshed out OpenMP implementation. - I/O stream support in the MSVCIRT C++ runtime. - Support for pixel snapping in DirectWrite. - More support for OpenGL core contexts. - Various bug fixes. Read more

Canonical Closes QEMU Vulnerabilities in Ubuntu 15.04 and Ubuntu 14.04 LTS

Three QEMU vulnerabilities have been found and corrected in Ubuntu 15.04 and Ubuntu 14.04 LTS operating systems by Canonical. Read more