let me try..
Looks fine to me. Only 1 CPU core I think was 100%.
10+0 records in
10+0 records out
10737418240 bytes (11 GB, 10 GiB) copied, 28,0695 s, 383 MB/s
ow.. now the idea is to unzip it right?
nice idea:
if (ipIsBlackListed() || isMalicious()) {
header("Content-Encoding: deflate, gzip");
header("Content-Length: "+ filesize(ZIP_BOMB_FILE_10G)); // 10 MB
readfile(ZIP_BOMB_FILE_10G);
exit;
}
Might need some
if (ob_get_level()) ob_end_clean();
before the readfile
. 😉
I want to know he they built that visualization
Interesting. I wonder how long it takes until most bots adapt to this type of "reverse DoS".
Then we'll just be more clever as well. It's an arms race after all.
macOS compresses its memory. Does this mean we'll see bots running on macOS now?
Is it immune to zip bombs?
All I know is it compresses memory. The mechanism mentioned here for ZIP bombs to crash bots is to fill up memory fast with repeating zeroes.
I thought it was to fill all available storage. Maybe it’s both?
No, but that's an interesting question. Ultimately it probably comes down to hardware specs. Or depending on the particular bot and it's env the spec of the container it's running in
Even with macos's style of compressing inactive memory pages you'll still have a hard cap that can be reached with the same technique (just with a larger uncompressed file)
How long would it take to be considered an inactive memory page? Does OOM conditions immediately trigger compression, or would the process die first?
So I'm not an expert but my understanding is the flow is roughly:
- Available memory gets low
- Compress based on LRU rules
- Use swap
- OOM
So it's more meant to be preventative afaik
This is why I use things like Docusaurus to generate static sites. Vulnerability injections are pretty hard when there's no code to inject into.
❤️
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.