DOS and Oversized Zip

Julian Field mailscanner at ecs.soton.ac.uk
Tue Feb 24 09:46:36 GMT 2004


At 00:39 24/02/2004, you wrote:
>There are ways to handcraft a zip file so it expands from a few
>bytes to a couple of terabytes, used to be called "The Zip of
>death". Clam allows you to restrict the compression ratio to
>avoid "Zip bombs" of this nature. Imagine the problems if you
>received a zip bomb that was a few hundred K compressed and a few
>gig uncompressed?

MailScanner is designed to handle this sort of attack, and should survive it.
--
Julian Field
www.MailScanner.info
MailScanner thanks transtec Computers for their support

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654



More information about the MailScanner mailing list