Update: search-for-compression.py Version 0.0.8
Update: search-for-compression.py Version 0.0.8 I’ve noticed when a zlib compresse 2026-9-30 07:33:32 Author: blog.didierstevens.com(查看原文) 阅读量:11 收藏

Update: search-for-compression.py Version 0.0.8

I’ve noticed when a zlib compressed chunk of data is followed by other data, search-for-compression.py will not always be able to detect the compressed chunk. This is caused by the fact that the other data generates a decompression error, and the complete chunk is disregarded.

I’ve added a new option to try to solve this: -S

Option -S takes a value, a positive number. It’s the size of the decompression buffer. By default, its value is 0.

When you try -S 100 for example, search-for-compression.py will try to decompress up to 100 bytes. If that succeeds, then we assume that we found compressed data, and search-for-compression.py will try to decompress the remainder of the data until either a decompression error occurs, or there is no more data. But when an error occurs, search-for-compression.py will revert to the last decompression without error, and report that.

search-for-compression.py is still in my beta repository.

No comments yet.


文章来源: https://blog.didierstevens.com/2026/09/30/update-search-for-compression-py-version-0-0-8/
如有侵权请联系:admin#unsafe.sh