Fuzzers

Статья про построение фермы для фаззинга: https://habr.com/ru/company/dsec/blog/517596/arrow-up-right

Dockerfiles for some fuzzers: https://github.com/WiseSecurity/dockerized-fuzzersarrow-up-right

WEIZZ: Automatic Grey-Box Fuzzing for Structured Binary Formats Slides: https://andreafioraldi.github.io/assets/weizz-issta2020-slides.pdfarrow-up-right Video: https://www.youtube.com/watch?v=MOeUqlFtgwEarrow-up-right Article: https://andreafioraldi.github.io/assets/weizz-issta2020.pdfarrow-up-right Code: https://github.com/andreafioraldi/weizz-fuzzerarrow-up-right

Fuzzing JavaScript Engines with Aspect-preserving Mutatio https://github.com/sslab-gatech/DIEarrow-up-right

Storm - a blackbox mutational fuzzer for detecting critical bugs in SMT solvers Article: https://numairmansur.github.io/STORM.pdfarrow-up-right Code: https://github.com/Practical-Formal-Methods/stormarrow-up-right

UAFuzz: Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities https://github.com/strongcourage/uafuzzarrow-up-right

radamsa https://gitlab.com/akihe/radamsaarrow-up-right создание мутаций из примеров Например:

# Generate 1000 example payloads
radamsa -n 1000 -o %n.txt example1.txt example2.txt

FLUFFI - фреймворк для "пентестров" для фаззинга бинарей https://github.com/siemens/fluffiarrow-up-right

Что специалисты из NCC Group использовали для фаззинга 5g protocols: https://research.nccgroup.com/2021/10/11/the-challenges-of-fuzzing-5g-protocols/arrow-up-right

ClusterFuzz — ферма фаззинга от Google

OneFuzz — ферма фаззинга от Microsoft

valgrind, addrsanitizer, bullseye, svace, libfuzzer, statsviz, AFL++

Last updated