XML: a growing security threat?

Wednesday, 29 October 2003, 2:19 PM EST

Is XML a security threat? A few years ago, that might have seemed a stretch to anyone using the standard as a way to encode and swap data. The emergence of Web services, however, is changing that. According to Gartner, most large firms already have or are planning some kind of Web services project within the next year.

One of the lures of Web services is the ease of exchanging data in XML format. Yet as companies have moved toward Web services, they’ve increasingly begun to tie disparate systems together to swap data in near- or real-time, and XML is the Web services lingua franca. Gartner says almost 70 percent of companies view security as a barrier to Web services deployment.

Hence an emerging threat: if malicious XML code were set to an application that automatically executed it, a company—and its Web services partners—could have problems. Microsoft’s release of Office 2003 adds another reason to be wary. One selling point of the new Office is that it includes new tools for collaboration and sharing. What enables that collaboration? XML.

[ Read more ]




Spotlight

Cloned, booby-trapped Dark Web sites steal bitcoins, login credentials

Apart from being a way for dissidents and journalists to do their business without being spotted and identified by "the powers that be", the Dark Web is also a place where criminals sell and buy illegal wares and services and, apparently, where they also get robbed by scammers.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Fri, Jul 3rd
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //