Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
meindnoch
1y ago
0 comments
Share
>I mean, the client device can also send zip bombs
A GET request doesn't have a body. There's nothing to gzip.
undefined | Better HN
0 comments
default
newest
oldest
mrtksn
1y ago
What if they send a POST request?
chgs
1y ago
Most servers will limit posts to a fairly low size by default.
mrtksn
1y ago
Yes but the idea behind zip bombs that they appear to be very small, when expanded it can be extremely large. Before attempting to decompress, the POST request may appear something like 20kb and end up being 20gb.
1 more reply
meindnoch
OP
1y ago
You close the socket as soon as you see "POST" and there's no POST handler registered.
mrtksn
1y ago
what if you accept post for legit reasons?
1 more reply
neallindsay
1y ago
GET requests usually don't have a body, but they can.
j
/
k
navigate · click thread line to collapse