Questions tagged [zip-bomb]

4 questions
7
votes
1 answer

How to protect websites against ZIP bombs and reference bombs?

A Zip bomb (concept here) seems quite a "smart" and easy vulnerability to websites where uploading ZIP files is allowed. Such sites are under a threat (at least to make some degree of damage to them) - someone uploads i.e. a 100 KB file [ 50 GB…
T.Todua
  • 2,677
  • 4
  • 19
  • 28
5
votes
2 answers

What are some possible uses of a zip bomb?

This article claims that zip bombs cannot be used today as modern systems are too smart for it and no victim is going to slowly unpack terrabytes of data so zip bombs are basically useless. Is this true? Are there any uses for a zip bomb at…
Vegeta
  • 51
  • 1
  • 2
1
vote
0 answers

How does the "ClaimLetter#.zip" attack work?

I wonder if this is the right place to ask about the specific functioning of viruses / worms. We all receive fishy mails all the time. And generally I never click on anything, especially not attachments purporting to be quotes, letters, sipping…
0
votes
2 answers

Why is PDF still safe?

Something I was wondering about after reading Didier Stevens Labs 2008 post: There are endless ways described how to put potential malicious content into a pdf file, while making it impossible for mask-based scanners to detect the content. If a pdf…
arc_lupus
  • 209
  • 1
  • 10