Zip bomb

Last reviewed:

A zip bomb, also known as a decompression bomb, is a malicious archive file designed to crash or render a system unusable by overwhelming it with data. It is a type of logic bomb that exploits the compression algorithms used in archive files like ZIP. When a zip bomb is decompressed, it expands into an enormous amount of data, consuming significant system resources and potentially causing a denial of service (DoS). Zip bombs are often used to disable antivirus software or other security measures that automatically scan compressed files.

Overview

A zip bomb is a form of attack that leverages the properties of file compression to disrupt systems. Unlike traditional malware, a zip bomb does not contain executable code that directly harms the system. Instead, it uses a large amount of data compressed into a small file to overwhelm the system's resources. When the file is decompressed, it expands to a size that the system cannot handle, to a crash or significant slowdown. Zip bombs are typically used to bypass security mechanisms, such as antivirus programs, by causing them to become unresponsive.

How it works

Zip bombs exploit the way compression algorithms work. Compression algorithms reduce the size of data by eliminating redundancy. A zip bomb contains highly redundant data that compresses into a small file size. When decompressed, this data expands exponentially. For example, a 42-kilobyte zip bomb can decompress into 4.5 petabytes of data. The decompression process consumes a large amount of memory and processing power, to a denial of service.

The most common type of zip bomb is a nested archive, where a compressed file contains another compressed file, and so on. This recursive structure can lead to exponential growth in data size when decompressed. Another method involves using a single file with highly redundant data that compresses efficiently but expands significantly when decompressed.

Applications

Zip bombs are primarily used as a form of denial of service attack. They are often employed to disable antivirus software or other security tools that automatically scan compressed files. By causing these programs to crash or become unresponsive, attackers can bypass security measures and deliver other forms of malware to the system.

In some cases, zip bombs are used as a test for system robustness. Security researchers and system administrators may use zip bombs to evaluate the effectiveness of security tools and the resilience of systems against resource exhaustion attacks.

Limitations

While zip bombs can be effective in overwhelming system resources, they have several limitations. Modern antivirus software and security systems often include protections against zip bombs. These protections can detect and block zip bombs by analyzing the compression ratio and structure of the archive file. Additionally, systems with sufficient resources may be able to handle the decompression process without crashing.

Zip bombs are also limited in their ability to cause lasting damage. Unlike other forms of malware, they do not execute malicious code or steal data. Their primary effect is temporary disruption, which can be mitigated by restarting the affected system.

In conclusion, zip bombs are a unique form of logic bomb that exploit compression algorithms to cause denial of service. While they can be effective in disabling security measures, their impact is often temporary and can be mitigated with modern security tools and practices.

How a Zip Bomb Works

Size Comparison of Zip Bombs

See also

Sources

Categories: Techniques | Malware
Last updated: October 2, 2026