Zip of Death

Raymond Dijkxhoorn raymond at PROLOCATION.NET
Mon Jun 9 21:01:33 IST 2003


Hi!

> Does anyone know how to create and/or defend against the zip of death? I
> have a piece of software (open-source, not developed by me) that I *think*
> is probably susceptible, but I don't know exactly how this attack works.
> I'd be happy to know how to defend against this (presumably by watching out
> for a loop in the decompression routing), or happier to have a sample to
> test with. PLEASE DON'T EMAIL IT LIVE!!!!

MS allready protects you from zip of death. Its nothing more then a zip
with a file inside thats very compressed, for example a file with a few
million zeros.

Bye,
Raymond.



More information about the MailScanner mailing list