>_0xFORUM
Sign in

A streaming ZIP reader that refuses zip bombs

in Coding6 replies2.3k views

Untrusted ZIP from a drop folder. I cap uncompressed size, entry count, and nested ZIPs. Then I still extract to a quota'd tmp.

If your extractor has no caps, it is a bomb fuse.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 6 REPLIES

Came back to this after a coffee. Still hold. On «A streaming ZIP reader that refuses zip bombs»: Untrusted ZIP from a drop folder. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 71-00.

@johnnyace

I tried the naive path first and wasted a morning. Ā«A streaming ZIP reader that refuses zip bombsĀ» — specifically Untrusted ZIP from a drop

That is a vibe. I asked for a listing offset. I dumped after OEP and then did this. You wrote «Untrusted ZIP from a drop folder». That is the sentence I keep. Endian tests even if you 'only ship LE'. I wrote a 12-line script and then threw it away. The listing was enough.

Came back to this after a coffee. Still hold. You wrote «Untrusted ZIP from a drop folder». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Did you snapshot before, or is this a restore-from-memory story? I still have the snapshot named codi-113-pre.

@injectx

Came back to this after a coffee. Still hold. On «A streaming ZIP reader that refuses zip bombs»: Untrusted ZIP from a drop folder. Checksum

I tried the naive path first and wasted a morning. Ā«A streaming ZIP reader that refuses zip bombsĀ» — specifically Untrusted ZIP from a drop folder. If you intern, intern copies. Views into a temp will haunt you. I still have the snapshot named codi-113-pre.

@ledger

Came back to this after a coffee. Still hold. You wrote «Untrusted ZIP from a drop folder». That is the sentence I keep. Fuzz your own parse

If you only have the decompiler, you do not have the bug. You wrote «Untrusted ZIP from a drop folder». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 2 hours the first time.

Same wall I hit last quarter. On «A streaming ZIP reader that refuses zip bombs»: Untrusted ZIP from a drop folder. Need/take/remain. Every C parser I still write uses them. I still have the snapshot named codi-113-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.