6 ms·
How to defend your website with ZIP bombs (2017)
- _V_ 3y agoI have something similar - except I don't send them ZIP bombs, but I engage in something akin to a Slowloris attack. I keep the connection open and send random bytes with random delays in between. To my surprise, I got few "champions" who spend >12h on a socket trying to get data that lead nowhere. And since there is ultimately a limit on number of sockets on a system, you can effectively DDoS that attacker.
- mglz 3y ago> This script obviously is not - as we say in Austria - the yellow of the egg, [...] I think my pig is whistling!
- zubairq 3y agoNice, I didn’t even know that ZIP bombs existed! I have seen some huge spam traffic on servers I run in the past so this will be a good tool for me to use. Thanks
- cyberax 3y agoTIL today: ZIP bombs are still a thing, 40 years after the first BBS.
- theshrike79 3y agoSimilar things were popular in the DC++ age too. Some servers required you to have X gigabytes of stuff in your shares, so you just had a zip bomb in your share with the correct size. It reported the size as 10GB to the server, but actually it took a few kilobytes on disk.
- iforgotpassword 3y agoI've done this without compression but just sending infinite data. On some days I've sent a TB to a single IP address... Might be an idea to combine this. I'd assume the resulting gzip file here contains a repeating pattern that you can generate on the fly?
- joshspankit 3y agoBack in the day if you had a faster modem and typed faster than the other person’s modem could receive, you could kick them offline. The more things change, the more they stay the same?
- tuyiown 3y agoA zip bomb is way more effective as it will be transferred very quickly and saturate attacker storage as fast as possible, with a good probability to make the system inoperable (login into a machine with with 0 storage left can be challenging).
- Retr0id 3y agoYes, it would be trivial to make an "endless" gzip stream.
- lifthrasiir 3y agoAnd if you need an explicit binary, it is very easy to make one. Prepare a large enough file filled with the same byte (or generate them on the fly), let gzip to compress it, then observe where the zero byte start to repeat. Cut everything after that point and repeat the zero byte from there on. In my system: $ head -c 10000000 /dev/zero | gzip -c -9 | hexdump 0000000 8b1f 0008 530a 659e 0302 c1ec 0101 0000 0000010 8000 fe90 eeaf 0a08 0000 0000 0000 0000 0000020 0000 0000 0000 0000 0000 0000 0000 0000 * 0002010 0000 0000 0000 db80 0383 0012 0000 4100 0002020 5fff 23b7 0150 0000 0000 0000 0000 0000 0002030 0000 0000 0000 0000 0000 0000 0000 0000 * 00025f0 0000 0000 0000 0000 0000 0000 0000 e000 0002600 cb26 3ba5 803e 9896 0000 0002609 So you can keep the first 0x18 bytes and repeat zero bytes after that, preferably very slowly. (The middle bit is an arbitrary block boundary, while the last bit is CRC-32 and the uncompressed size which the client will never see.) I have also used `-c` option to avoid the original file name in the result, which precedes the compressed data.
- inglor_cz 3y agoWas your hosting OK with that? ZIP bombs are light on the "data transferred" front, a TB is pretty massive.
- nicbou 3y agoHad it had a marked effect on the bots? Dropping *.php calls helped a lot.
- reaperman 3y agoIs it legal to purposefully distribute a malicious payload as a booby trap?
- JohnFen 3y agoI don't think that a zip bomb counts as "malicious". I can't think of a law (in the US) that would prohibit doing this sort of thing.
- Avamander 3y agoIt's a joke answer at best, plus if someone would go complain, their actions for discovering the booby trap were illegal anyways.
- ksjskskskkk 3y agonever link to it and add to robots.txt digital castle doctrine or whatever.
- artiscode 3y agoIs it really malicious though? 10 gigs of zeros doesn’t seem that malicious to me. Microcontrollers often have a few megabytes of RAM if not less, does that make a few megabyte photo malicious? Edit: spelling. I’m old school and used to typing on my computer. It’s getting repaired and all I’ve got is my phone. /rant
- deleted 3y ago[deleted]
- esdf 3y agoI wouldn’t try it in Japan https://github.com/hamukazu/lets-get-arrested https://github.com/hamukazu/lets-get-arrested
- ehPReth 3y agohttps://42.zip https://42.zip served just that (after the 42.zip named on https://en.wikipedia.org/wiki/Zip_bomb https://en.wikipedia.org/wiki/Zip_bomb) until some ****hole reported it to Google/etc for.... phishing? Kinda sad, lol. One of the arguments I've seen is: 'what if your antivirus scans it' to which I think: if your antivirus blows up on a zip bomb in 2024, you need a new antivirus that isn't total garbage?
- geek_at 3y agoThis could be the result of a google indexing error. Strangeley enough my blog (the one linked in this hn post) itself was de-listed from google justa few weeks ago. The Blog is a static HTML page with no external dependencies and I didn't even update it in the time google thought there was phishing somewhere. The Webmastertools showed the error but didn't link to any specific site (it even said null). So i sent it in to re-evaluate and it was put back on google (without changing anything on the static files themselves). Very strange stuff
- koito17 3y agoIf I recall correctly, HTTP clients do not need to care about Content-Encoding at all and can choose to just not do anything with your ZIP bomb. To really hit them, you will want to do this at the Transfer-Encoding level.
- deleted 3y ago[deleted]
- lifthrasiir 3y agoIf the client wants to parse HTML and do something accordingly, it at least has to honor some popular Content-Encoding.
- _xnmw 3y agoIn the spirit of a good offence is the best defence, etc., I wonder if there are any other ways to defend my website.
- stareatgoats 3y agorelated: https://news.ycombinator.com/item?id=14707674 https://news.ycombinator.com/item?id=14707674 (July 6, 2017 — 183 comments)
- hannob 3y agoPeople have been coming up with ideas like that regularly. I'm not a fan. The title says that you can "defend" your webpage, but it is not clear how it "defends" against anything. The only thing you possibly achieve is that every now and then, someone with an automated scanner (which may be an attacker, or may be a security researcher or service) will see his tool crash or consume large amounts of resources. You're spending time trying to annoy attackers that you should probably just ignore. If you really worry that someone running some automated scanner against your webpage causes you any harm, you probably should spend your time with something different than building zip bombs, and instead fix the security problems you have.
- JohnFen 3y ago> The only thing you possibly achieve is that every now and then, someone with an automated scanner (which may be an attacker, or may be a security researcher or service) will see his tool crash or consume large amounts of resources. True. But it's also a low-cost, low-effort thing. It may not change the world, but putting a small hiccup in someone's operation can bring a small bit of joy.
- Avamander 3y agoSlowing down and resisting unauthorised scanners does sound like one more layer of defence to me.
- bayindirh 3y ago> you probably should spend your time with something different than building zip bombs, and instead fix the security problems you have. Why not both? You can both create a well configured server to reduce its attack surface and add a booby-trap or two for really adamant scanners which hit very specific endpoints on your site. I don't have to welcome every scanner with open arms. Maybe I'm doing some research, PoC||GTFO style, and your scanner found my research. It's not my problem.
- Freak_NL 3y ago> PoC||GTFO style ?
- cosmin800 3y agoNot sure it works for the scanners, sure it crashes the browsers, but I would guess most scanners use libcurl which has a callback function for saving data and would give up on loading the resource if over 2MiB let's say.
- o-o- 3y agoAnother method that stuck with me: in the early days of bitcoin someone built an "ssh paywall" – i.e. you would pay to enable ssh remote authentication for a minute or two. In essence a hacker would have to pay before attempting to hack the ssh endpoint. Of course the admin would have to pay too but the money would end up on his/her wallet. Quite ingenious if you ask me.
- joshspankit 3y agoStuff like this is going to be wild when digital transaction fees for tiny amounts are basically free and transactions can be truly anonymous.
- lifthrasiir 3y agoIf the client supports Brotli, this attack can be made much more effective because the maximum compression ratio of Brotli is much higher than gzip. DEFLATE used by gzip has the maximum ratio of 1032:1 because each run can emit at most 258 bytes and need at least 2 bits, but Brotli allows zero bits per code when there is only one code possible. So Brotli's result only depends on the underlying metablock overhead, but sadly each metablock can contain at most 2^24 - 1 uncompressed bytes (because that uncompressed size is encoded per each metablock, while DEFLATE needs a separate end-of-block code). Still this translates to at least 1000000:1 ratio so it's worthwhile.
- Avamander 3y agoThis can also be done with nginx's gzip_static/brotli_static, somewhat easier. One similar technique against port scanners is to send ~50% rejects and do ~50% drops in the case of closed ports. Most of them will pollute their output or slow down tremendously assuming packet loss.
- justsomehnguy 3y ago> How to defend your website with ZIP bombs .. or more like 'How to retaliate when you think too much of your [website] importance'. While the ability to (maaaaybe) crash the crawler sounds nice it probably doesn't do what do you think. At best you just snapped off one head of Hydra, only more to come. Also using PHP instead of the web-server's path actions...
- PolGZ 3y ago[dead]
- 13of40 3y agoIt reminds me of someone I read about from the early web who defended their website against email address harvesting crawlers by adding a dynamic page that threw up some random emails and links, where the links just led back to the dynamic page under a new path on the same host. The crawlers would get stuck downloading millions of fake email addresses until they eventually broke.
- InfamousRece 3y agoI used wpoison back then: https://www.gsp.com/support/virtual/web/cgi/lib/wpoison/ https://www.gsp.com/support/virtual/web/cgi/lib/wpoison/
- kxrm 3y agoGuilty, I did this on my first project site back in the early 00s. It only worked for a small time before scanners got more sophisticated. It was a fun diversion but people who do this quickly adapt.
- Log_out_ 3y agoWhat if the returned content is just chat gpt generated add hoc nonsense in the amount nonsense heuristics-1 ?
- mcqueenjordan 3y agoThis reminds me of the chat bot tool that was deployed to reply to scam emails and waste maximal time of the scammers by seeming like a vulnerable, gullible target. The chat bot would drag out the interaction slowly, wasting as much time as possible for the scammer, all the while posing as a real human. There are a lot of comments here decrying this as a method to defend your website, but in some senses it's a very smart tactical weapon, especially if deployed widely. There's an often quoted phrase in making secure password hashes that you're not making it impossible to crack, only prohibitively expensive to do so such that the benefits don't outweigh the costs. The same principle applies here -- if the good guys collectively make scanning a very expensive endeavor, the juice is no longer worth the squeeze for the bad guys. Just blocking an IP is cheap for them. Make them bleed a little.
- mcqueenjordan 3y agoAnother possible tactic is to trickle your packets back slowly, say trickle 1 TCP packet back to them per second. Sure, they probably have client-side timeouts, but again, if everyone did this, wouldn't it be a pain to scan for vulns? Every endpoint you hit would last the duration of your timeout.
- pixl97 3y agoDo modern bots deal with TARPITTING better? This was something that was pretty common years ago when dealing with bots.
- mcqueenjordan 3y agoThis is a great reference. I hadn’t seen this before. Thanks. No idea about the effectiveness now vs then.
- naich 3y agoI tried the example with FF on Ubuntu, and it had no effect whatsoever. It didn't even use up any memory. Are browsers protecting against this now?