• Site Info
    h2


    Podango

    • podPress
    • Click to donate thru PayPal
    • Mighty Forums
    • Email
    • Instant Messenger

    FREE Security Scan from NT OBJECTives, Inc

    Create Animations With Stickman

    Custom Plugins

    Podcast/Blog
    h2

    Podcast Links

    • Podcast Feed
    • Blog Feed
    • View in iTunes
    • Mighty Seek on PodcastAlley.com
    • Mighty Seek on PodcastPickle.com
    • Sites that link to here
    • Podcasting Setup
    • Check out our Frappr!

    WebAppSec Links

    Categories

    Archives

    Yahoo


Mighty Seek
home

Misc Postings

h1

Dan with Friends of the Fringe

Monday, October 2nd, 2006

I sat in with the LA Podcasters gang at the PPME and was in on a recording of Friends of the Fringe, which was pretty fun.

Im the guy on the right with the green shirt and this hat

h1

MightySeek coming back online slowly

Wednesday, September 13th, 2006

We had a total system failure, and of course I didnt have a backup worth using to get things back online. I am working to get the site fully back up and will be doing so as quickly as possible,

Mighty Seek

h1

Questions for podcast with Dan (PodPress developer)

Thursday, May 18th, 2006

James Woodcock will be interviewing me in the coming days, and so posted this on the forums.

Click here to get to the forum topic

Dan (Mighty Seek) developer of the PodPress plugin for Wordpress, will be interviewed in one of my future blogcasts on my website.

If you have any questions you would like him to answer about either his PodPress plugin or security, please ring my automated (non-premium) voicemail on UK: 0207 193 3092 or Worldwide: +44 207 193 3092 or for free on skype id: glidem

The best questions will be included in the show…..
__________________
>> Hear more about PodPress, in my audio interview with Dan Kuykendall <<

http://www.jameswoodcock.co.uk - My personal online diary covering the internet that I find of interest including audio interviews, music, gaming, technology, gadgets, websites, free downloads and general articles.

h1

For-Pay Only Podcasting (Password Protected)

Monday, March 13th, 2006

Today I learned about iTunes support for password protected podcasts, and am thinking about the security issues, planning out how I can support this in PodPress as well as what this means for podcasting in general.

Overall I think this is very cool for podcasting, because it can open the doors for various content providers to jump in and start offering content. It may also allow existing podcasters to start offering special pay-only content. I know many want everything for free, but Im not opposed to paying people for the time and talent they pour into creating great content.

That aside, I was most curious about the technical issues involved. So I dug in…

Last week I heard that radio talk show host Rush Limbaugh announced that his show would be available from within iTunes. For several months his show was available as a “podcast” which meant his subscribers could download MP3’s a few hours after each show aired. At the time this happened, I dug into the custom downloader, sniffed out the traffic and figured out how it all worked. It wasnt complicated, but it wasnt a real podcast, there was no RSS feed with enclosures, and no way standard podcatchers could ever support it.

Now the landscape has changed, and this is a new solution that works with iTunes. I still didnt know how it was going to work, but my guess was that it had to do with HTTP BasicAuth. This morning the website had the link, and I had my Paros Proxy. I configured my computer to run thru the local proxy, and I went about getting the show into my iTunes, recording all the network traffic along the way.

It turned out to be much easier than I expected. It did use HTTP BasicAuth, and it only does so for the rss feed.
So what we have is a link to the RSS feed, but with the protocol defined as itpc, which I assume to mean ITunesPodCast and is something that iTunes is registered to handle.

So the link looks something like this:

itpc://rss.premiereradio.net/podcast/rushlimb.xml

Note: Just because the protocol is itpc instead of http, does not mean you couldnt go to this URL with your browser

http://rss.premiereradio.net/podcast/rushlimb.xml

If you try, you will get a password prompt. This is using standard HTTP BasicAuth, and once you give your credentials you would get the RSS Feed.
The feed itself is a standard iTunes compliant RSS2 document like we are all used to. As far as the MP3 files themselves, there is only security by obscurity. I will not give an actual URL to one of the MP3 files, but its something along the lines of

http://rss.premiereradio.net/download/rushlimb /username/48123789787qe98/rushlimb/2006/03/ Rush%20Limbaugh%20-%20Mar%2010%202006%20-%20Hour%201.mp3

If you had the actual URL, you could download the MP3 without any sort of authentication. Of course, security by obscrurity is not an ideal solution, but in the case of this type of content it serves the need. It should also be easy use the same HTTP BasicAuth to protect the MP3 files is so desired.

I have also found out that the popular podcatcher Juice supports HTTP BasicAuth as well, so using this solution really seems the way to go.

I believe I can add support into PodPress for all this at some point, and the bottom line is that this is an interesting and exciting development in the Podcasting world.

- Additional Resources -

* Just found out about another blogger who did a write up here

* http://juicereceiver.sourceforge.net

 
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast
Mighty Seek Podcast, MightySeek Podcast, Mighty Seek Blog, MightySeek Blog, Web application security podcast, Web application security blog, Web application development blog, Web application development podcast