6 ms·
Is there any way to detect these things before unzipping them?
by blodovnik 7y ago
Is there any way to detect these things before unzipping them?
- gtsteve 7y agoIt looks reasonably easy - the main thing you're looking for local file headers that are referenced multiple times by the central directory. This is not invalid itself of course - some compression programs likely deduplicate files with this technique. But if it seems excessive, or it's the only thing in the archive then you've got a zip bomb. You could probably come up with some techniques to obfuscate this of course but it'll increase the size of the archive.
- rwmj 7y agoWhenever you download any untrusted file and attempt to parse or unpack it (and this includes zips, tarballs, PDFs, even images) your program should fork off some kind of sandbox which limits CPU time, memory, disk space, and access to local resources such as the filesystem and system calls. There are various sandboxing technologies from using simple rlimit, or a cgroup, or even running a full VM (see libvirt-sandbox) depending on the threat level and the amount of effort you want to put in vs the perceived risk.
- Hitton 7y agoI run unzip -l, it tells you which files are how big are inside.