Recent Articles

Microsoft to Remove XML Support from Word
In a previous patch for MS Office, Microsoft removed support for custom XML according to an article from Computerworld. This is a result of an injunction i4i won against Microsoft. It prevents Microsoft from...

New Syncro Soft XML Editor and Author Release
Syncro Soft, the privately owned software company who is known for their expertly written XML programs, has released a new version of their editing and authoring systems. They’re both called Oxygen XML...

Two Leading XML Solution Experts To Host Webinar...
For those who have problems with content overload or content misuse, a webinar is being hosted which could present you with solutions. When an enterprise has content which is vital to making a deadline...

01.26.10

XML Used To Exploit Twitter Flaw

By Doug Caverly

It looks like XML is going to become a hot (or at least warm) topic at the upcoming Black Hat Technical Security Conference. Apparently a researcher’s discovered a problem affecting Twitter and a number of other sites, and he’s been able to exploit it using an XML file.

Dan Goodin reported late last week, “The error resides in an Adobe Flash object hosted on the microblogging site, said Mike Bailey, a senior security analyst with penetration testing firm Foreground Security.  Contrary to Adobe recommendations, the object is free to load files hosted virtually anywhere on the net, including those containing booby-trapped javascript and action script.”

A lot of important companies have supposedly made the same mistake, too, and Bailey intends to “out” them all at the security conference.

Host Unlimited Websites - Only $7.95 a Month
Get Started Now

In terms of reputation and public relations, this might not be the best way for XML to receive more attention; let’s hope no one comes to think of it as a hacker’s tool.  Still, publicity is publicity, and people who attend the conference will likely be smart enough to recognize XML’s usefulness in all sorts of situations.

The Black Hat Technical Security Conference will take place between January 31st and February 3rd in Washington, D.C., so stay tuned.


About the Author:
Doug is a staff writer for WebProNews. Visit WebProNews for the latest eBusiness news.
About xmlProNews

xmlProNews is a collection of news and commentary designed to keep you in step with the ever evolving landscape of XML environments. News and Advice for XML Professionals





xmlProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com SysAdminNews.com






-- XMLProNewsis an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2010 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


XMLProNews