Big Bunches of Ebooks in Little Packages
Silk Pagoda
Olympia Press
Disruptive Publishing
Brown Paper Publishing
Akashic Books
Soft Skull
Echelon Press
Action (859)
Adventure (0)
Australia (162)
Biography (708)
Canada (265)
Children (1760)
Classic (787)
Comics (1)
Critics (549)
Drama (486)
Education (226)
Elizabethans (101)
Enlightenment (5)
Esoteric (107)
Europa (1616)
Fiction (5161)
Folklore (188)
History (1399)
Horror (987)
Liberal Arts (178)
Mystery (718)
Nautical (612)
Nonfiction (339)
Orient Express (269)
Periodicals (439)
Philosophy (273)
Poetry (982)
Political Science (163)
Pulp Fiction (602)
Reference (82)
Religion (793)
Renaissance (69)
Satire (245)
Science (114)
Science Fiction (628)
Travel (73)
Unclassified (4553)
Western (137)
 
The .epub security hole 26/09/2007

Reg is running a story about malware getting stuck into .pdfs.  Nothing to add there, seems pretty complex to make 'em.

Related, I asked Bill McCoy, vp of Adobe, about how easy it was for me to stick just anything into an .epub file (audio/video files), given that the "standard" is just a .zip file that's read whole by a several applications (er, at at least one).  Of course, I could have stuck nasty virii into my fake epub as well... it would still load, albeit slowly.

McCoy's answer:


There could be some value to reporting on the presence of such “junk DNA” riding along in an epub “assembly”, possibly are part of the authoring/distribution tool workflow if not for end users. This is something we will take a look at.

He adds:

This has nothing to do with the container format being based on ZIP or not. PDF utilizes its own intrinsic container format (informally called “COS”) and it’s also possible to insert unused objects therein, although we recognize that this is superficially easier for end users to do with a ZIP-based archive, people trying to spread malware would likely have software tools at their disposal anyway. And one reason a ZIP-based approach was chosen is for ease of authoring and manipulation. It is also the basis for storage of OpenOffice (ODF format).


So I feel better.  Though many email programs will, after all, just block .zip files... and the ODF format does not appear to allow applications.
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=office

Thank god for secure standards.
 
  Add Comment

  Copyright © 1998-2008 Disruptive Publishing. Some Rights Reserved. Terms and Conditions  

Warning: fclose(): supplied argument is not a valid stream resource in /home/munsey/public_html/end_cache.php on line 9