Download the PHP package mleczakm/zip-bomb-honeypot without Composer
On this page you can find all versions of the php package mleczakm/zip-bomb-honeypot. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download mleczakm/zip-bomb-honeypot
More information about mleczakm/zip-bomb-honeypot
Files in mleczakm/zip-bomb-honeypot
Package zip-bomb-honeypot
Short Description Symfony event subscriber that traps vulnerability scanners probing for common exploit paths (.env, wp-admin, PHP shells, ...) by serving a small, highly compressible zip bomb instead of a 404.
License MIT
Informations about the package zip-bomb-honeypot
zip-bomb-honeypot
A Symfony event subscriber that traps vulnerability scanners and bots probing for common
exploit paths — .env, wp-admin, PHP shells, SQL dumps, .aws/credentials, etc. — by
serving a small, highly compressible zip bomb instead of a 404.
The zip bomb is built from the "overlapping local file headers + DEFLATE quoting" technique described in David Fifield's USENIX WOOT 2019 paper "A better zip bomb": a single highly-compressed "kernel" is referenced by many overlapping local file headers, so the file on the wire stays tiny (a few hundred bytes by default) while unzip tools that don't guard against overlapping entries can expand it to gigabytes.
Install
Usage
In a Symfony app with autoconfiguration enabled (the default in services.yaml), the
subscriber is picked up automatically once it's registered as a service:
That's it — any request whose path matches a known scanner pattern (checked both on the
initial kernel.request and again on a resulting 404 via kernel.exception) gets a zip
bomb response instead of continuing through routing or your 404 page.
What it matches
See MaliciousRequestPathMatcher for the exact
pattern list — PHP file probes, .env* files, .aws/, WordPress paths, common config/backup
filenames, .vscode/, *.sql dumps, and app_dev.php/.
Tuning the payload
HoneypotResponder builds the response via ZipBombGenerator::generate(), which you can call
directly if you want a different size/shape:
License
MIT
All versions of zip-bomb-honeypot with dependencies
symfony/event-dispatcher Version ^6.4 || ^7.0 || ^8.0
symfony/http-foundation Version ^6.4 || ^7.0 || ^8.0
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0