ZIP BOMBS vs. Windows

preview_player
Показать описание
Do you know what a ZIP bomb is? Did you know that Defender is struggling with it? Watch this video for a dive into the peculiarities of ZIP bombs.

0:00 - Intro
0:12 - #1: What is a ZIP bomb?
1:04 - #2: So, what's the problem?
4:28 - #3: Better ZIP bombs
6:52 - #4: Self-replicating ZIP
10:20 - Conclusion and Outro
----------------------------

Join the channel's discord server "The Flying Tech"!

Follow me on Twitter:

----------------------------

License: Creative Commons Attribution 3.0

License: Creative Commons Attribution 3.0

#lookinside #zipbombs #flytech
Рекомендации по теме
Комментарии
Автор

Windows Defender: DO NOT Extract its a zip bomb

Windows Defender : Let me do that for you

johncruelty
Автор

windows defender: warning: that's a zip bomb! I'll remove it.
also windows defender: tries to extract it.

satibel
Автор

- Wait, so the real virus is actually Windows Defender?
- Always has been.

djole
Автор

*feel free to keep working while we take action*

SSD - 100% utilization

KSR
Автор

Yes, the greatest way to remove a zip bomb. Extract it. Amazing logic, really.

ponivi
Автор

Isn't this like... decades old? Good job, Microsoft.

chillshobe
Автор

*Zip Malware is literally older than Windows itself*
Windows: oh I know what this is! *extracts*

mgord
Автор

Defender: "Don't extract it! Just keep working, we'll take it from here."
Also Defender: *Extracts the zip bomb, causing SSD utilization to hit 100%, essentially brings computer to its knees*

vapor-sings
Автор

2:49 Windows Defender: Feel free to keep working while we detonate bomb right under your seat.

ankitminz
Автор

Windows defender identifying a threat from the DOS age and still managing to screw it up.

christinaandwena
Автор

You’re telling me the Big Bang was just a cosmic zip bomb prank gone wrong?

MNGN
Автор

It can be paired with a malware so that Windows defender purely focuses on scanning zip bomb and in the mean time malware does its job unnoticed

xerogaming
Автор

This shows both the power of zip compression and how dumb Windows Defender is.

gustavo_colombini
Автор

defender, where's the zip bomb?
see its right here i tried to extract it in order to remove it
you were supposed to just delete it
dude im gonna
oh really?
yes
so go and try to delete it
(disk usage 100%)
i see the problem
oh DO YA

Misuune
Автор

The real question from me though is, has anyone been affected legitimately by a zip bomb? I've been using the internet for over a decade and a half now and literally just heard about these for the first time. I feel like Defender would need a pretty big rework to deal with zip bombs as it would have to change its way of dealing with removing and extracting threats. Perhaps it's sufficient for it to warn you instead of taking immediate action?

GamerOrmer
Автор

no one:

**me extracting this on the schools servers**

hyenatube
Автор

Am i the only one that thinks that Flytech is a more humble version of Enderman?

drmick
Автор

The fly looks great clicking the YouTube buttons

jello
Автор

I think what a lot of people are failing to realize, is that Windows Defender saw the original 42.zip and nuked it before FlyTech could do anything with it. But the encrpyted version has a different file hash, and the contents (lib*.zip) didn't have the zip bomb hash either.

When he created a new zip file via Explorer, the resulting filesize was 547KB. The original is 42KB... The hash, without even having to actually hash it to check, is different.

So why does this mean Windows Defender did nothing wrong? Because when scanning the zip file, it needs to extract the contents of the zip file to hash them to see if they are a known threat.

To really explain how AntiViruses work would be far too in-depth for a youtube comment, and I only have a very very high level understanding of them at that, but ultimately Windows Defender did it's job. The known 42.zip, which is named 42.zip because it's a zip file with the filesize of 42KB that explodes to a massively larger filesize, was detected and deleted immediately.

MushokuThing
Автор

WinDefender trying to remove the ZIP bomb by extracting it is an equivalent of a sapper trying to deactivate the landmine by stepping on it

templays