3 ms·
>> ... eventually filled up the entire disk and bad things happened I can only imagine what would have happened. Can you share more details about that. Also,
by fromdoon 14y ago
>> ... eventually filled up the entire disk and bad things happened
I can only imagine what would have happened. Can you share more details about that.
Also, wonder how the mail servers these days are equipped to handle such attachments. Can someone throw light on that? Is it just plain simple to detect these files?
- tonyz 14y agoA well-known example of a zip quine: http://steike.com/code/useless/zip-file-quine/ http://steike.com/code/useless/zip-file-quine/ Compression quines and bombs are a great way to screw up automated systems. Possessing or transmitting them can easily cause a denial of service. From Wikipedia: A quine is a computer program which takes no input and produces a copy of its own source code as its only output. http://en.wikipedia.org/wiki/Quine_(computing) http://en.wikipedia.org/wiki/Quine_(computing)
- krenoten 14y agoComputational complexity attacks are actually quite rampant in various types of software. A good example is an "evil regex" which is usable on software that accepts regular expressions as input, and similarly costly regexes already contained in software can be exploited by certain crafted input to induce a DOS. http://en.wikipedia.org/wiki/ReDoS http://en.wikipedia.org/wiki/ReDoS
- omh 14y agoAll of the email virus scanners I've used are aware of this sort of thing, and will have a maximum depth or maximum size for scanning within attachments. I don't think any of them try to "detect" them in any cleverer way.
- lignuist 14y agoSo I should just place my malicious software deeper than n levels or put it in a huge file? Or are those scanners just rejecting files that are too large or deep?
- DanBC 14y agoYou used to be able to just password protect the file, and instruct users to enter the password. Some malware is remarkably unsophisticated and relied on users installing it and giving it permissions to run. I hope they're not silently rejecting files.
- krenoten 14y ago"The Grugq: I’m not joking. You don’t even need to do that. You just send an e-mail which says, you can literally just say, "Run this code." Some of the anti-phishing guys I’ve worked with are just shocked at what happens. I had some friends who worked in corporate security who had to do a cleanup after they got hit with e-mails which said literally, "click on this" and they had 10 or 20 people who did. It was less than 1 percent, but it was enough. People will do it and even on a locked-down corporate PC, it doesn’t matter. If you can get an HTTP connection back out to the Web, you can then tunnel in over that." (The Grugq sells high value 0days and is a respected member of the hacking community) http://www.csoonline.com/article/216370/where-is-hacking-now-a-chat-with-grugq?page=4 http://www.csoonline.com/article/216370/where-is-hacking-now...
- SoftwareMaven 14y agoThat was how RSA was breached, which led to the eventual loss of the SecureID master key (and follow-on breeches at DoD suppliers).
- philiac 14y agoWhat does RSA stand for? I was on their (SecurID) related site, and checked out the "about" page, but the acronym is never defined.
- sokoloff 14y agoInitials of the three inventors (discoverers?) of the algorithm: http://en.wikipedia.org/wiki/RSA_(algorithm) http://en.wikipedia.org/wiki/RSA_(algorithm)