// Hacking NEWS // Once Decompressed, This 46 MB Zip File Reaches 4500 TB!

in news •  5 years ago 

A new kind of Zip bomb has been created, reaching a compression ratio of 28 million. Little pranksters abstain.

hqdefault.jpg
Source

A developer brings the "Zip bombs" up to date. Using a file overlay technique, David Fifield was able to create a file with a compression ratio of 28 million, or even 97 million using the Zip64 format.

This is the first time someone has reached such a ratio without using recursive compression (a Zip file included in a Zip file, etc.). In other words, this file "expands completely after a single round of decompression," says the expert in a blog note.

Zip bombs have been around since the 1990s. One of the most famous is 42.zip, a 42 kb compressed file that, once opened, reaches 4.5 Po. This represents an incredible compression ratio of 106 billion.

However, this ratio is achieved by using six levels of recursivity, knowing that at each level, a Zip file decompresses 16 new Zip files.

Of course, it is not recommended to decompress such a file on a computer, nor to send it to someone. It would be a bad taste joke.

Anti-virus software usually detects this type of file before the user has time to click on it. But this is not yet the case for this last generation.

According to VirusTotal, only eight out of 42 software programs currently detect it, including Kaspersky, Eset and DrWeb. Fourteen other antivirus software programs grind to a halt when they fall on it ("timeout"). But it's only a matter of time.

According to David Fifield, the detection of his bombs would be "easy".

“I hope that one of the benefits is more awareness among developers of the hazards of processing complex archive formats like Zip,” he added. “It helps to have some concrete outputs: code reviewers, customers, and users will at least be able to point to this research and ask, does it handle this correctly?”

Source: David Fifield's blog note, Vice

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!