Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > News

Notices

Reply
 
Thread Tools Search this Thread
Old 07-29-2024, 01:43 PM   #1
DNSB
Bibliophagist
DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.DNSB ought to be getting tired of karma fortunes by now.
 
DNSB's Avatar
 
Posts: 40,417
Karma: 156982136
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
Malware and pirated ebooks

Interesting item in The Hacker News on pirated ebooks now being used by ViperSoftX malware for attacks. There have been proof of concept ebooks with malware for years but looks like they have finally been weaponized though this is more due to using .rar archives to store them.

See ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks for more information.
DNSB is offline   Reply With Quote
Old 07-29-2024, 02:14 PM   #2
Sirtel
Grand Sorcerer
Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.Sirtel ought to be getting tired of karma fortunes by now.
 
Sirtel's Avatar
 
Posts: 11,449
Karma: 230178176
Join Date: Jan 2014
Location: Estonia
Device: Kobo Sage & Libra 2
Seems to me that the ebooks themselves don't contain malware, the archives do. Why should anyone want to run an unknown executable from a random rar archive when they actually wanted an ebook is beyond me, but people are capable of doing some very stupid things.
Sirtel is online now   Reply With Quote
Advert
Old 07-29-2024, 02:25 PM   #3
theducks
Well trained by Cats
theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.
 
theducks's Avatar
 
Posts: 30,441
Karma: 58055868
Join Date: Aug 2009
Location: The Central Coast of California
Device: Kobo Libra2,Kobo Aura2v1, K4NT(Fixed: New Bat.), Galaxy Tab A
Many (Many) years ago, I had a case where Norton AV, checking my email, actually caused the deployment of a virus in an archive attachment.
(They fixed that flaw within hours)
The actual e-mail was SPAM, that I did not even open and sent to the bit bucket.. But the damage was already done.
theducks is offline   Reply With Quote
Old 07-29-2024, 02:49 PM   #4
Quoth
the rook, bossing Never.
Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.Quoth ought to be getting tired of karma fortunes by now.
 
Quoth's Avatar
 
Posts: 12,329
Karma: 90943357
Join Date: Jun 2017
Location: Ireland
Device: All 4 Kinds: epub eink, Kindle, android eink, NxtPaper11
Quote:
Originally Posted by Sirtel View Post
Seems to me that the ebooks themselves don't contain malware, the archives do. Why should anyone want to run an unknown executable from a random rar archive when they actually wanted an ebook is beyond me, but people are capable of doing some very stupid things.
Agree with all of that.


I think it must be a slow aday for Hacker News.
Quoth is offline   Reply With Quote
Old 07-29-2024, 02:51 PM   #5
j.p.s
Grand Sorcerer
j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.
 
Posts: 5,520
Karma: 100606001
Join Date: Apr 2011
Device: pb360
Quote:
Originally Posted by Sirtel View Post
Seems to me that the ebooks themselves don't contain malware, the archives do.
That might change, since EPUBs support javascript.
j.p.s is online now   Reply With Quote
Advert
Old 07-29-2024, 02:54 PM   #6
JSWolf
Resident Curmudgeon
JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.
 
JSWolf's Avatar
 
Posts: 76,337
Karma: 136006010
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
Quote:
Originally Posted by Sirtel View Post
Seems to me that the ebooks themselves don't contain malware, the archives do. Why should anyone want to run an unknown executable from a random rar archive when they actually wanted an ebook is beyond me, but people are capable of doing some very stupid things.
Click here to infect your computer

OK. CLICK
JSWolf is offline   Reply With Quote
Old 07-29-2024, 04:49 PM   #7
Cactus Chef
Addict
Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.Cactus Chef ought to be getting tired of karma fortunes by now.
 
Cactus Chef's Avatar
 
Posts: 382
Karma: 6324692
Join Date: Apr 2019
Device: Kobo Sage, Kobo Clara HD, Galaxy Tab S5e, Kindle 4th Gen
Do RAR's even offer much compression on an EPUB? The other day I was trying to send my wife some EPUBs over email and tried zipping them to get them under the 25mb attachment limit, but the ZIP file barely shaved more than a meg or two off the filesize versus just sending the EPUBs individually. 7-zip wasn't much better, and I couldn't guarantee that she had 7-zip installed on her PC. I ended up just sending her two emails.
Cactus Chef is offline   Reply With Quote
Old 07-29-2024, 05:01 PM   #8
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,038
Karma: 199464182
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Hardly matters on Windows these days. Defender is flagging/deleting just about every downloaded archive that contains executables as a severe threat (including executables that Defender doesn't flag when downloaded uncompressed). Quite annoying actually. You don't want to tell Defender to stop scanning ALL downloaded archives, but ... sheesh! Not everything out there is Wacatac.B!ml. Dial it down a notch Microsoft!
DiapDealer is offline   Reply With Quote
Old 07-29-2024, 05:19 PM   #9
j.p.s
Grand Sorcerer
j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.j.p.s ought to be getting tired of karma fortunes by now.
 
Posts: 5,520
Karma: 100606001
Join Date: Apr 2011
Device: pb360
Quote:
Originally Posted by Cactus Chef View Post
Do RAR's even offer much compression on an EPUB?
An EPUB is a zip file. Zipping a zip is never going to give significant further compression. In some cases the file will get larger. Using a different general purpose compression algorithm on an already well compressed file will be unlikely to result in significant further compression.
j.p.s is online now   Reply With Quote
Old 07-29-2024, 06:27 PM   #10
ownedbycats
Custom User Title
ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.ownedbycats ought to be getting tired of karma fortunes by now.
 
ownedbycats's Avatar
 
Posts: 9,514
Karma: 64500171
Join Date: Oct 2018
Location: Canada
Device: Kobo Libra H2O, formerly Aura HD
Quote:
Originally Posted by Sirtel View Post
Seems to me that the ebooks themselves don't contain malware, the archives do. Why should anyone want to run an unknown executable from a random rar archive when they actually wanted an ebook is beyond me, but people are capable of doing some very stupid things.
From the article:

Quote:
Attack chains propagating the malware are known to employ cracked software and torrent sites, but the use of eBook lures is a newly observed approach. Present within the supposed eBook RAR archive file is a hidden folder as well as a deceptive Windows shortcut file that purports to be a benign document.
Quote:
Attack chains propagating the malware are known to employ cracked software and torrent sites, but the use of eBook lures is a newly observed approach.
Yeah, it's an issue with RAR files, not ePubs or AZW3s or MOBis. That RAR could be holding a cracked game or a bunch of porn pics and still have the malware.

A few years ago there was a "WinRAR" vulnerability - except it wasn't actually WinRAR, it was a vulnerability in unacev2.dll and would affect any archive program using that specific library.

Last edited by ownedbycats; 07-29-2024 at 07:00 PM.
ownedbycats is online now   Reply With Quote
Old 07-29-2024, 08:44 PM   #11
jackm8
Addict
jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.jackm8 ought to be getting tired of karma fortunes by now.
 
jackm8's Avatar
 
Posts: 212
Karma: 2818790
Join Date: Nov 2015
Device: none
Quote:
Originally Posted by ownedbycats View Post
From the article:
Yeah, it's an issue with RAR files, not ePubs or AZW3s or MOBis. That RAR could be holding a cracked game or a bunch of porn pics and still have the malware.

A few years ago there was a "WinRAR" vulnerability - except it wasn't actually WinRAR, it was a vulnerability in unacev2.dll and would affect any archive program using that specific library.

I don't think that it's about rar files at all. If I read this right, there's a shortcut that looks like a book file (kamasutra.epub.exe), that then installs this trojan.

Quote:
Present within the supposed eBook RAR archive file is a hidden folder as well as a deceptive Windows shortcut file that purports to be a benign document.
jackm8 is offline   Reply With Quote
Old 07-29-2024, 08:54 PM   #12
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,038
Karma: 199464182
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
How does kamasutra.epub.exe look like a book file? Surely even the most novice potential book thief knows that ebooks aren't executables.
DiapDealer is offline   Reply With Quote
Old 07-29-2024, 09:16 PM   #13
PeterT
Grand Sorcerer
PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.PeterT ought to be getting tired of karma fortunes by now.
 
PeterT's Avatar
 
Posts: 12,731
Karma: 75000000
Join Date: Nov 2007
Location: Toronto
Device: Libra H2O, Libra Colour
Quote:
Originally Posted by DiapDealer View Post
How does kamasutra.epub.exe look like a book file? Surely even the most novice potential book thief knows that ebooks aren't executables.
Remember that by default Windows does not display file type.... So after expanding the archive they will see kamasutra.epub in the folder....
PeterT is offline   Reply With Quote
Old 07-29-2024, 09:33 PM   #14
theducks
Well trained by Cats
theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.theducks ought to be getting tired of karma fortunes by now.
 
theducks's Avatar
 
Posts: 30,441
Karma: 58055868
Join Date: Aug 2009
Location: The Central Coast of California
Device: Kobo Libra2,Kobo Aura2v1, K4NT(Fixed: New Bat.), Galaxy Tab A
Quote:
Originally Posted by PeterT View Post
Remember that by default Windows does not display file type.... So after expanding the archive they will see kamasutra.epub in the folder....
and the reverse is also true.
If that (no ext)is set, then RED flag if there is one showing

LOGIC
I get security emails from my bank (and ISP) Frequently.
The Flag??? They come in on the WRONG email account. Many ISP allow alias/additional mailboxes as part of your subscription.

Hint: The bank never uses my theducks account
theducks is offline   Reply With Quote
Old 07-29-2024, 09:33 PM   #15
DiapDealer
Grand Sorcerer
DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.DiapDealer ought to be getting tired of karma fortunes by now.
 
DiapDealer's Avatar
 
Posts: 28,038
Karma: 199464182
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
Quote:
Originally Posted by PeterT View Post
Remember that by default Windows does not display file type.... So after expanding the archive they will see kamasutra.epub in the folder....
I get that, but I'm still not seeing why this is an ebook thing. In my mind, anything that might possibly make people think twice about downloading illicit versions of ebooks from pirate sites (or gets their computer trashed for being ignorant/arrogant enough to do so) is a good thing. This is not a reason to fear being infected by legitimate ebook resources.

There's certainly vectors in ebooks themselves that can be exploited, but this doesn't seem like one of them. Any reading engine that allows epubs to access/modify files outside of the ebook's own archive (without the user giving explicit permission for them to do so via default preferences modification) is a shoddy reading engine.

Last edited by DiapDealer; 07-29-2024 at 09:37 PM.
DiapDealer is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Copyright & Pirated eBooks KyBunnies General Discussions 16 03-14-2017 06:11 PM
Pirated ebooks on Google Play? GeoffR General Discussions 12 02-04-2015 01:27 AM
Top 10 Most Pirated Ebooks of 2009 Sonist News 42 05-22-2010 11:00 PM
The 10 Most Pirated eBooks of 2009 yagiz News 50 09-09-2009 09:02 AM
Pirated ebooks on Amazon? Daithi Amazon Kindle 27 07-16-2009 03:07 PM


All times are GMT -4. The time now is 07:05 PM.


MobileRead.com is a privately owned, operated and funded community.