<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Decompression Bombs Part 2</title>
	<atom:link href="http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/feed/" rel="self" type="application/rss+xml" />
	<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/</link>
	<description>Technology. Code. Living relentlessly in the real world.</description>
	<lastBuildDate>Sun, 18 Jul 2010 14:29:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: LOLZ</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-34543</link>
		<dc:creator>LOLZ</dc:creator>
		<pubDate>Sun, 15 Mar 2009 05:23:00 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>Gary: To your response to spoonie, why just spit on them, I suggest cutting teh bodys into many little pieces, placing them in a blender, grinding them into liquid, dumping it into their bath tub, and then defecating in it. :P</description>
		<content:encoded><![CDATA[<p>Gary: To your response to spoonie, why just spit on them, I suggest cutting teh bodys into many little pieces, placing them in a blender, grinding them into liquid, dumping it into their bath tub, and then defecating in it. :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-34175</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Wed, 18 Feb 2009 01:24:56 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>Firstly, it&#039;s not too hard to make a bomb on a unix machine. I&#039;d think a command like
&#039;dd if=/dev/zero bs=1M count=100000 &#124; gzip &gt; bomb.gz&#039;
would do it. Make 100GB of zeros in 1Mb chunks and send that to gzip

Also, it&#039;s not strictly speaking true that sending one in email has no potential for a profitable attack. you could bomb their mail-servers and then send in other malware attached to emails, banking on them turning off their mail scanning at least temporarily to stop the attacks. Blow a hole in their scanning for a bit.
Pretty ineffective I&#039;d say, but in theory possible.</description>
		<content:encoded><![CDATA[<p>Firstly, it&#8217;s not too hard to make a bomb on a unix machine. I&#8217;d think a command like<br />
&#8216;dd if=/dev/zero bs=1M count=100000 | gzip &gt; bomb.gz&#8217;<br />
would do it. Make 100GB of zeros in 1Mb chunks and send that to gzip</p>
<p>Also, it&#8217;s not strictly speaking true that sending one in email has no potential for a profitable attack. you could bomb their mail-servers and then send in other malware attached to emails, banking on them turning off their mail scanning at least temporarily to stop the attacks. Blow a hole in their scanning for a bit.<br />
Pretty ineffective I&#8217;d say, but in theory possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Solitude &#187; Decompression Bombs</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-20554</link>
		<dc:creator>Solitude &#187; Decompression Bombs</dc:creator>
		<pubDate>Thu, 24 Apr 2008 18:59:25 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>[...] Decompression Bombs Part 2 outlines some real-life examples and answers a few [...]</description>
		<content:encoded><![CDATA[<p>[...] Decompression Bombs Part 2 outlines some real-life examples and answers a few [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Fleming</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-13757</link>
		<dc:creator>Gary Fleming</dc:creator>
		<pubDate>Wed, 26 Dec 2007 13:20:28 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>Never using a zip program, like Winzip, is an over-reaction (and a pretty untenable position to take). Just be sensible about what you open.</description>
		<content:encoded><![CDATA[<p>Never using a zip program, like Winzip, is an over-reaction (and a pretty untenable position to take). Just be sensible about what you open.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tiffany</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-13591</link>
		<dc:creator>Tiffany</dc:creator>
		<pubDate>Sun, 23 Dec 2007 00:39:20 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>If I never use winzip will I be safe? Like a dumbass I just opened the file to see what would happen. Nothing. It opened, all is fine. (or is it?)
My antivirus program has me thinking that it&#039;s a virus and my computer will crash the next time I reboot.</description>
		<content:encoded><![CDATA[<p>If I never use winzip will I be safe? Like a dumbass I just opened the file to see what would happen. Nothing. It opened, all is fine. (or is it?)<br />
My antivirus program has me thinking that it&#8217;s a virus and my computer will crash the next time I reboot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danny</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-13070</link>
		<dc:creator>Danny</dc:creator>
		<pubDate>Wed, 12 Dec 2007 10:22:58 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>when you open an archive with winzip, does it auotmatically load the compressed data into memory? shouldnt you be able to check the compression ratio and compare to the file size?</description>
		<content:encoded><![CDATA[<p>when you open an archive with winzip, does it auotmatically load the compressed data into memory? shouldnt you be able to check the compression ratio and compare to the file size?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Fleming</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-9253</link>
		<dc:creator>Gary Fleming</dc:creator>
		<pubDate>Wed, 17 Oct 2007 21:02:55 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>J: you&#039;re right, it&#039;s not a new trick, but still pretty effective, particularly against browsers.

Wilk: Hmm... not sure. I would guess they would be accurate.</description>
		<content:encoded><![CDATA[<p>J: you&#8217;re right, it&#8217;s not a new trick, but still pretty effective, particularly against browsers.</p>
<p>Wilk: Hmm&#8230; not sure. I would guess they would be accurate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wilk</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-9250</link>
		<dc:creator>wilk</dc:creator>
		<pubDate>Wed, 17 Oct 2007 20:32:57 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>I have an old copy of winzip that shows the unzipped file size and the compression percentage.  Will these fields be accurate or will they be spoofed by the bomb?</description>
		<content:encoded><![CDATA[<p>I have an old copy of winzip that shows the unzipped file size and the compression percentage.  Will these fields be accurate or will they be spoofed by the bomb?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-9229</link>
		<dc:creator>J</dc:creator>
		<pubDate>Wed, 17 Oct 2007 13:47:31 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>This is a pretty old trick. Years ago when BBS&#039;s would unzip all .zip files that were uploaded (to add advertisements, strip other BBS advertisements, scan, etc.), you could send this sort of &quot;bomb&quot; and crash the BBS. I never thought of using it in modern times, though. Nice article!</description>
		<content:encoded><![CDATA[<p>This is a pretty old trick. Years ago when BBS&#8217;s would unzip all .zip files that were uploaded (to add advertisements, strip other BBS advertisements, scan, etc.), you could send this sort of &quot;bomb&quot; and crash the BBS. I never thought of using it in modern times, though. Nice article!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Fleming</title>
		<link>http://solitude.vkps.co.uk/Archives/2006/01/11/DecompressionBombsPart2/comment-page-1/#comment-9175</link>
		<dc:creator>Gary Fleming</dc:creator>
		<pubDate>Tue, 16 Oct 2007 21:26:53 +0000</pubDate>
		<guid isPermaLink="false"></guid>
		<description>mike: in theory, yes, you can probably aggravate the situation by picking an awkward time but the situations you describe just wouldn&#039;t happen.

Having a single server for mail and transaction processing? Not even the smallest of banks with a technology footprint would do that.

Also, you can&#039;t &quot;insert a virus... through email&quot; due to the server being down. If the server is down, you can&#039;t send to it. There is no avenue for attack.

So: using known timing attacks to really cause havoc, absolutely. Using decompression bombs for further attack, not so much.</description>
		<content:encoded><![CDATA[<p>mike: in theory, yes, you can probably aggravate the situation by picking an awkward time but the situations you describe just wouldn&#8217;t happen.</p>
<p>Having a single server for mail and transaction processing? Not even the smallest of banks with a technology footprint would do that.</p>
<p>Also, you can&#8217;t &#8220;insert a virus&#8230; through email&#8221; due to the server being down. If the server is down, you can&#8217;t send to it. There is no avenue for attack.</p>
<p>So: using known timing attacks to really cause havoc, absolutely. Using decompression bombs for further attack, not so much.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
