Have you ever heard of the term ZIP bombs? The term refers to nested ZIP files that, when unzipped, release huge files that the victim's computer cannot process in its memory or cannot store on disk.
For example, a 5 petabyte file containing only zeros can easily be compressed to 48 kilobytes, because the ZIP compression system can handle repeated data extremely well, multiplying the compression ratio.
ZIP bombs: What do they do?
ZIP bombs have been used in recent decades as a way to defeat antivirus software, which is configured to scan ZIP files by decompressing the file and examining its contents.
This didn't last long, of course, as antivirus software companies added protection against ZIP bombs. However, there are still applications that are exposed to these files, such as browsers or applications that scan for vulnerabilities, such as Nikto, SQLMap , and others.
But let's see how it can also be used against malicious users who try to connect to or hack private websites.
Austrian tech expert Christian Haschek has created two PHP scripts that can detect specific user strings and create ZIP bombs for browsers or vulnerability scanners that attempt to access secure or private web pages (such as admin panels, backends, or login forms).
These scripts will replace the normal page that the hacker expected to find with one that contains ZIP bombs. Once the applications they use receive the ZIP bomb, they will try to process the data and the attacker's computer will crash.
Most browsers and scanners will stop working!
In the table below, Haschek details how some applications behave when they encounter a ZIP bomb.
| Client | Result |
|---|---|
| IE 11 | Memory leaks, IE crashes |
| Chrome | Memory increases, error shown |
| Edge | Memory rises, then drips and loads forever |
| Nobody | Seems to scan fine but no output is reported |
| SQLmap | High memory usage until crash |
| Safari | Hight memory usage, then crashes and reloads, then memory rises again, etc.. |
| Chrome (Android) | Memory increases, error shown |
The PHP scripts required to create a ZIP bomb for vulnerability scanners are available on Haschek's page.
Below is a demo for browsers, be careful because the browser you are using may stop working and you may lose your current session.
Attention
https://blog.haschek.at/tools/bomb.php
