logoalt Hacker News

cuechanlast Friday at 10:37 PM2 repliesview on HN

Is it possible to implement something similar but with a protocol that supports compression? Can we have a zip bomb but with a compressed http response that gets decompressed on the client? There are many protocols that support compression in some way.


Replies

dontdoxxmelast Friday at 11:08 PM

Previously: I use zip bombs to protect my server (idiallo.com) 1076 points https://news.ycombinator.com/item?id=43826798

moreatilast Friday at 11:20 PM

There was https://idiallo.com/blog/zipbomb-protection earlier this year. It sends highly compressed output of /dev/zero. No overlapping files or recursively compressed payloads.