This article delves into an innovative zip bomb technique that achieves non-recursive extraction by overlapping files within the zip container, reaching compression ratios up to 28 million (10MB to 281TB). The core of the technology leverages the uncompressed block feature of the DEFLATE algorithm, referencing highly compressed kernel data to avoid recursive extraction. The author provides detailed analysis of construction methods, optimization strategies such as efficient CRC-32 calculation and filename management, and compares different algorithms (like bzip2) and extensions (such as Zip64). This research offers deep technical insights, demonstrates the boundaries of compression technology, and provides practical recommendations for defending against resource exhaustion attacks, holding significant value for the cybersecurity field. The source code and test data have been open-sourced, making it suitable for reference by security researchers and developers.
Original Link:Hacker News
最新评论
I don't think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.
这个AI状态研究很深入,数据量也很大,很有参考价值。
我偶尔阅读 这个旅游网站。激励人心查看路线。
文章内容很有深度,AI模型的发展趋势值得关注。
内容丰富,对未来趋势分析得挺到位的。
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?
光纤技术真厉害,文章解析得挺透彻的。
文章内容很实用,想了解更多相关技巧。