4 ms·
You might want to take a look at jsfunfuzz[0][1] or this USENIX paper[2] by Christian Holler, Kim Herzig and Andreas Zeller, called "Fuzzing with Code Fragments
by mrngm 2y ago
You might want to take a look at jsfunfuzz[0][1] or this USENIX paper[2] by Christian Holler, Kim Herzig and Andreas Zeller, called "Fuzzing with Code Fragments" (which also references [0]; two of the paper's authors contributed to the fuzzing book).
Based on your description and the overlap in authors, LangFuzz, as presented in the paper, seems to match quite close. Roughly summarizing a few paragraphs of the paper, they mainly used a mutational approach (e.g. modifying already found/generated "inputs") after a learning phase where sample files are processed and their grammar discovered (section 3.1 in [2]). This leads to code fragments that are syntactically correct, but might be semantically incorrect (see section 3.3 in [2])
Another fuzzer (albeit more recently in time) that has found numerous vulnerabilities is afl-fuzz, or "american fuzzy lop"[3].
[0] https://www.squarefree.com/2007/08/02/introducing-jsfunfuzz/ https://www.squarefree.com/2007/08/02/introducing-jsfunfuzz/
[1] https://blog.mozilla.org/security/2007/08/02/javascript-fuzzer-available/ https://blog.mozilla.org/security/2007/08/02/javascript-fuzz...
[2] [PDF] https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final73.pdf https://www.usenix.org/system/files/conference/usenixsecurit...
[3] https://lcamtuf.coredump.cx/afl/ https://lcamtuf.coredump.cx/afl/