Help - Search - Members - Calendar
Full Version: Watchout for the Bomb
Vault9 Forums > Tech Den > Binary Refinery > The Backdoor
LegendofMax
Yup, i was unfortunatly to get a Zip_bomb on my pc this morning.

The info:

What is it? Well its exactly what is says.... a .Zip file that has about 2 Terrabytes of useless crap ont (single word files with no text)
How do you get it? Well there are almost anyway to get it: Emails, Downloads, you name it. I got mine from a "friend" over Msn.
What happens when you get it? Nothin really.
What happens when you OPEN it? Congrats you are a retard like me. It tries to transfer (unpacking 2 terrabytes all at once is not fast).
What symptoms do you get? Instant super slow CPU and crashing of CPU consuming programs i.e Games and Office.
What happens to your pc? Its being over run by a load of crap. Once this process is done, your pc will crash. GG.

Possible scenerios:

1. Okay, It's on my pc but it have not even clicked it yet, what to do? Good, you are safe. Delete and empty recycling bin. Solved
2. I accidentley opened it, but did not extract any files, what to do? (This is what happened to me) immidiatly goto taskbark and stop all user owned processes except your anti-virus/spam, explorer.exe and ccapp.exe. Delete zip file (if it says "program in in use try later" then use a third party delete program, like [what i used] DrDelete) reboot pc. Solved.
3. Oh crap i opened and extracted the files. Now hundreds of files are popping up. HELP! PULL THE PLUG RIGTH NOW!! Stop the process from spreading. Now bootup in Safemode. Now find the root file and Delete it (if it doesnt you should use a third party program to delete it). Once that is done go for the minor unzips that are made. After that its cleanup duty: mop any escaped files and keep empting your bin.

Other important info:

It might comeback! Depending on what you've done if you did scenerio 1 or 2 you should be okay. If you followed 3 then there is a chance one zip file might be hinding in your root files or your anti-virus programs. Best thing to do is update anti-spam and get CCleaner. Hope it doesnt bother you again.
Its not spamware so it wont steral personal details Relax. Its made to crash your pc and loose your files, no need to worry on back security details.
Check regulary for slow running cpu. Every now and then check your CPU usage. It should NEVER reach more than 90% unless you are running like 15 programs at once. If so you might have a few Zips hiding somewhere.

Worst case scenerio:

You lose all your files and pc turns into a speed capacity of a toaster. Reformat is only option im afraid.



Finally you can read up on this matter futher if you are concerned about this.

Wikipedia Zip_Bomb


Safe surfing
~LOM
Gitano
Or just don't be a Muppet and download crap from anywhere without confirming its actually coming from your 'friend' ?
Paul
my sentiments exactly
Mr. Magic Matrix
For god sakes.

He is just trying to help, and people like us meet people on the net who have been helpfull and nice for a while and then sned u stuff like this to have a joke!
LegendofMax
Exactly, if u dont want my help fine then, fuck this i wont post a thread like this again
rurounikenshin
Well I'll take this advice and forward it onto my idiot users at my client.

They open any attachment that they receive and then moan about the problems as if it's my fault.

Thank Max!
Paul
I think Gitano's advice s more sound than any reactive measures anyone can take when it comes to dealing with things like this.

While JC's post is informative, nothing can compare to a proactive approach to dealing with virii and the like and that simply means don't open dodgy emails or files sent to you.

nice post jc.
Gitano
Paul = korrektamundo
Just add what I said into the original post dude, that all. Nice and easy, no need to get snotty about it all.

Is eskom having problems today? Because there is serious sense of humour failure all around.
docmoo
i thought eskom provided electricity, not laughter dry.gif
Paul
no, laughter would be korrek, cause they are a bunch of clowns over at eskom
RustPuppet
Extracting an unknown archive someone sent you over MSN? Sorry, but that's an uber-noob move and is just asking for trouble.

Besides, why are you extracting a zip without opening it in WinRAR/7-Zip/whatever first and seeing exactly what the contents are? It's a good practice to get into, lets you check for potentially dodgy/enormous files before unleashing them on your system.

Personally I always do a quick scan (both virus and content check) of a zip file's contents before extracting it, regardless of where I download it from. I'm completely paranoid that I get hit by something like Brontok again, or that evil MP3-killing biatch ermm.gif
Paul
QUOTE(RustPuppet @ Sep 10 2007, 08:26 AM) *
I'm completely paranoid that I get hit by something like Brontok again, or that evil MP3-killing biatch ermm.gif


mp3 killing biatch?

explain ?
RustPuppet
A virus went around recently which deleted MP3s from your machine, apparently.

Think it was called 'deletemusic' or something apt like that.
Paul
lovely

I think its time I converted all my music to ogg vorbis.
rurounikenshin
QUOTE
A virus went around recently which deleted MP3s from your machine, apparently.

Think it was called 'deletemusic' or something apt like that.


Seriously?!

That's a bad one!

The music industry must've written it!
RustPuppet
Apparently they did.
Valheru
QUOTE(RustPuppet @ Sep 10 2007, 01:30 PM) *
Apparently they did.

Metallica again? Lawsuit!!

laugh.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.