11 ms·
I found a similar file to this (a zip file that contains itself) and e-mailed it to a friend at work. He never received it, but I thought nothing of it (I assu
by jefffoster 14y ago
I found a similar file to this (a zip file that contains itself) and e-mailed it to a friend at work. He never received it, but I thought nothing of it (I assumed the email filters just destroyed it).
A days later the mail server stops working and the sysadmin turns up at my desk. Turns out the anti-virus scanner had been unzipping and scanning repeatedly. It eventually filled up the entire disk and bad things happened.
- deleted 14y ago[deleted]
- fromdoon 14y ago>> ... eventually filled up the entire disk and bad things happened I can only imagine what would have happened. Can you share more details about that. Also, wonder how the mail servers these days are equipped to handle such attachments. Can someone throw light on that? Is it just plain simple to detect these files?
- tonyz 14y agoA well-known example of a zip quine: http://steike.com/code/useless/zip-file-quine/ http://steike.com/code/useless/zip-file-quine/ Compression quines and bombs are a great way to screw up automated systems. Possessing or transmitting them can easily cause a denial of service. From Wikipedia: A quine is a computer program which takes no input and produces a copy of its own source code as its only output. http://en.wikipedia.org/wiki/Quine_(computing) http://en.wikipedia.org/wiki/Quine_(computing)
- krenoten 14y agoComputational complexity attacks are actually quite rampant in various types of software. A good example is an "evil regex" which is usable on software that accepts regular expressions as input, and similarly costly regexes already contained in software can be exploited by certain crafted input to induce a DOS. http://en.wikipedia.org/wiki/ReDoS http://en.wikipedia.org/wiki/ReDoS
- omh 14y agoAll of the email virus scanners I've used are aware of this sort of thing, and will have a maximum depth or maximum size for scanning within attachments. I don't think any of them try to "detect" them in any cleverer way.
- lignuist 14y agoSo I should just place my malicious software deeper than n levels or put it in a huge file? Or are those scanners just rejecting files that are too large or deep?
- DanBC 14y agoYou used to be able to just password protect the file, and instruct users to enter the password. Some malware is remarkably unsophisticated and relied on users installing it and giving it permissions to run. I hope they're not silently rejecting files.
- krenoten 14y ago"The Grugq: I’m not joking. You don’t even need to do that. You just send an e-mail which says, you can literally just say, "Run this code." Some of the anti-phishing guys I’ve worked with are just shocked at what happens. I had some friends who worked in corporate security who had to do a cleanup after they got hit with e-mails which said literally, "click on this" and they had 10 or 20 people who did. It was less than 1 percent, but it was enough. People will do it and even on a locked-down corporate PC, it doesn’t matter. If you can get an HTTP connection back out to the Web, you can then tunnel in over that." (The Grugq sells high value 0days and is a respected member of the hacking community) http://www.csoonline.com/article/216370/where-is-hacking-now-a-chat-with-grugq?page=4 http://www.csoonline.com/article/216370/where-is-hacking-now...
- SoftwareMaven 14y agoThat was how RSA was breached, which led to the eventual loss of the SecureID master key (and follow-on breeches at DoD suppliers).
- chrismorgan 14y agoThat reminds me of an incident when I was in year 8: seeing how deeply nested I could get directories on Windows. H:\a\a\a\a\..., eventually it stopped working. (I played the game with my friend... he went for creating a new directory at each level, after a little I became sensible and went for copying and pasting, thus multiplying the depth by two each level which of course achieves the goal pretty quickly - so I won by a considerable margin.) The school IT manager (who, incidentally, apart from this once I was always on good terms with) was rather annoyed at me the next day, for the nightly backup had fallen over the previous night and he had found the problem. You see, what to me was H:\ was \\galaxy\users$\chrism, which on that server was D:\users\chrism. So that 256-or-so character path became longer than 256 characters on the server and the backup software hadn't been written carefully enough to cope with what was a perfectly valid NTFS path, but not a valid path for the normal Win32 API function calls. How was I to know it would do that?
- jamoes 14y agoMy brother did this exact same thing (competing with his friend to try to make as many folders as possible), only he got a 1 week suspension for "hacking". The IT manager was really pissed and pressed the school administrators to make an example out of them. I was outraged. Basically, the IT manager preferred to use punishment as his means of security, rather than actually doing his job.
- johngalt 14y agoBeing able to break something =/= IT not doing their job. Tossing a brick through a window doesn't mean that the window should have been thicker.
- adimitrov 14y agoExcept that this was not 'tossing a brick,' it was maybe knocking on a window to see what sound it makes, and the window then falling apart for no apparent reason. There is nobody to blame for this, actually. Neither could the kid have known that this was bad (and the child-like curiosity is hardly something worth a punishment,) nor could the sysadmin really do anything to prevent it, except hang up a memo: please don't do that. Though, in that case, you'd have some kids doing that over and over again out of a very different kind of curiosity.
- makmanalp 14y agoThis is why you set up monitoring. You could notice either a) the long-lasting cpu-eating subprocess or b)just the rapid diminishing of disk space.
- keeperofdakeys 14y agoWhen I did a databases class at a University a few years back, we were given a share on a webserver to run php programs on. Naturally they didn't turn off php error logging, and by default php doesn't report errors to the user. One of the students accidentally wrote an infinite-loop, that generated an error on each iteration, filling up the disk. They never did fix the problem, just deleted the log file both times it occurred.
- gcr 14y agoThat's hilarious -- the viros scanner, which is designed to protect the mail server, was what wound up destroying it in the first place.
- khuey 14y agoThe virus scanner is designed to protect the mail server's clients.