Get 20% off all career paths from fullstack to AI
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course analyzes the security of EPUB reading systems through semi-automated testing of 97 applications and case studies of Apple Books, EPUBReader, and Amazon Kindle. It examines JavaScript, local and remote resource access, exploit techniques, mitigation, and the feasibility of distributing malicious EPUB files.
Syllabus
How Your E-book Might Be Reading You: Exploiting EPUB Reading Systems
The e book ecosystem
Semi-automated black-box evaluation
JavaScript support Inline
Remote communication
Local file system access
Web engine evaluation
Results (3)
Case studies
Apple Books
EPUBReader: implementation
EPUBReader: exploit strategy
EPUBReader: putting the exploit together
Amazon Kindle: implementation
Amazon Kindle: exploitation (2)
Amazon Kindle: mitigation
Capability (ab)use in the wild
Feasibility of e-book distribution
Key takeaways
Taught by
Black Hat