4 ms·
Not necessarily because the fuzzer has visibility into the execution pathways triggered, so it can "feel" its way through the maze. For example, say any certif
by gravescale 2y ago
Not necessarily because the fuzzer has visibility into the execution pathways triggered, so it can "feel" its way through the maze.
For example, say any certificate that starts with 0x00 is invalid (and there's an up-front test and return). Once the fuzzer has tried 0x00 and concluded that the pathway is a dead end, it won't try again, even though there are squillions of data blocks beginning 0x00.
It's not a highly efficient way to generate a valid certificate (especially when you have to navigate the network code as well), but it's also not just rolling 'n' 256-sided dice until the end of the universe.
- cjbprime 2y agoI think the parent is pointing out that if the signature has to be both syntactically and cryptographically valid, then this would defeat the fuzzer for obvious reasons. But I don't think it does, for this vulnerability. The signature is checked last.
- capitainenemo 2y agoYep. That was what I was thinking. Didn't realise the signature was checked later. Thanks for the clarification.