4 ms·
Fuzzing is super powerful, but can be a bit complicated to set up - that's why I'm working on a fuzzing-as-a-service platform[1] that automates a bunch of the s
by evmunro 8y ago
Fuzzing is super powerful, but can be a bit complicated to set up - that's why I'm working on a fuzzing-as-a-service platform[1] that automates a bunch of the steps described here.
If you're interested in trying out fuzzing without having to learn the intricacies of AFL or set things up manually, let me know[2] and I can get you set up with an account to play around with.
Happy to answer any questions about AFL/Fuzzbuzz!
[1] https://fuzzbuzz.io https://fuzzbuzz.io
[2] everest [at] fuzzbuzz [dot] io
- rixrax 8y agoWhat kind of closed source / commercial software can be fuzzed on your platform? E.g. how would you fuzz something like Adobe Lightroom or Autodesk AutoCAD there? What kind of reports would you provide?
- andrei 8y agoThe nature of fuzzers like AFL is that you get better results by instrumenting your code and writing your own harness, but AFL has a "qemu mode" that runs precompiled binaries in an instrumented VM instead. We'll be adding this to the platform in the near future. You won't get the same kind of results that you could by writing your own harness, but it would still be possible to find crashes, extreme memory usage or timeout bugs. Using something like libdislocator [1] would allow you to expose certain memory bugs as well. [1] https://github.com/mirrorer/afl/tree/master/libdislocator https://github.com/mirrorer/afl/tree/master/libdislocator
- kvakil 8y agohow does this compare to oss-fuzz [0]? is the main value proposition that its easier to set up? [0]: https://github.com/google/oss-fuzz/ https://github.com/google/oss-fuzz/
- andrei 8y agoHey - I'm the other guy working on Fuzzbuzz It's similar to oss-fuzz in terms of functionality, in that it lets you integrate fuzzing into your dev workflow by automatically pulling your latest code, fuzzing in the background, alerting you on bugs, running regression testing, etc. It differs in that while oss-fuzz is only for select large open-source projects, Fuzzbuzz lets anyone sign up and begin fuzzing their code. We also support more languages - the usual C/C++ as well as Golang, Python and Ruby, with more in the pipeline.