http://lpoaj774fddyczsopqwpecbqanp243yjaz36bukhzqgafkmwlxrhhuqd.onion/posts/2024/07/zipbombing.html
But, this seems even more effective, since we can make them download sth that unpacks into much more than 10GB (while having an innocuous content size at first). Now, the method as described in the original post had several issues: bots/scanners not supporting compression would still get a gzipped file more efficient methods than gzip (such as brotli or zstd) weren't considered ‒ tbf we dunno'f brotli or zstd give away their uncompressed size in metadata, we do know that...