3 ms·
Speaking of fuzzing, does anybody know of a solution for fuzzing multi-step processes? Suppose I was fuzzing a network application, which requires an entire ses
by d33 7y ago
Speaking of fuzzing, does anybody know of a solution for fuzzing multi-step processes? Suppose I was fuzzing a network application, which requires an entire session for a bug to be discovered. I can't do that with vanilla afl-fuzz; what tool would enable me to fuzz, say, an SSL/TLS library?
- wyldfire 7y ago> Suppose I was fuzzing a network application, which requires an entire session for a bug to be discovered I/O is a general problem for fuzzing and IMO the simplest/most general approach is to try and decompose the code under test to find a part that is able to accept a single input stream. EDIT: e.g. for an SSL/TLS library -- if you had a bool msg_create(msg_t *msg, void *input, size_t len_bytes) function, you could fuzz that one easily.
- agroce 7y agoIf you want to fuzz a library by making a series of calls, DeepState has special support for that, but that won't handle some other issues with network applications of course.
- caf 7y agoFor something like an SSL/TLS library, you could have a fuzzing mode that sets the initial randomness to a fixed value. That lets you create a pre-baked input file that can successfully establish a session, and you'd start the fuzzing from there. You can do the same thing with session IDs or similar. In general when you're fuzzing you want to fix your random seeds (and date/time inputs etc, as well as reset any external data store modified by the program back to initial conditions) - ideally your program being fuzzed is a pure function of its input.