5 ms·
SSH has some kind of compression, so if you can write a Twisted ssh server sending the file as a compressed ssh packed. For detection, fail2ban provides a plugi
by sametmax 7y ago
SSH has some kind of compression, so if you can write a Twisted ssh server sending the file as a compressed ssh packed. For detection, fail2ban provides a plugin architecture that allows it to do any action once it noticed an abuse, so you could switch the regular ssh implementation with you tricky one on the fly.
Fun project.
One should also do a lua nginx plugin for that: aggressive crawler ? Comment spammer ? Take this nice gzip HTTP response...
- vbezhenar 7y agoDoes it work with gzip?
- sametmax 7y agoNot sure, but let's see if I can try without crashing my laptop. EDIT: nope, steaming doesn't work, the zip relies on the fact it contains many files, and gzip assume there is only one big blog. EDIT 2: tried with zlib but it expects a different header. So my guess is you really need to open it as an archive.
- masklinn 7y agogzip and zlib (and tar) are "streaming" formats, the essay notes that "streaming" zip libraries are not affected as this bomb exploits the relationship between the central directory and the individual files.
- WAHa_06x36 7y agoThis file exploits the zip container format, not the actual compression algorithm. SSH only uses the latter, not the former, so it is not applicable.
- aflag 7y agoWould it be possible to do it just exploiting the algorithm?
- WAHa_06x36 7y agoYou can make some limited deflate bombs, but they are nowhere near as massive as this one.
- zaarn 7y agoYou don't need a zip file; just send the other side a gzip response with an endless amount of '<div>' inside. I've had some fun with that and some bots truly just stop responding after about 8 minutes of downloading div tags with no end.