4 ms·
Any fuzzer needs to compare its results to AFL (American Fuzzy Lop), "a free software fuzzer that employs genetic algorithms in order to efficiently increase co
by WalterGR 1mo ago
Any fuzzer needs to compare its results to AFL (American Fuzzy Lop), "a free software fuzzer that employs genetic algorithms in order to efficiently increase code coverage of the test cases." https://en.wikipedia.org/wiki/American_Fuzzy_Lop_(software) https://en.wikipedia.org/wiki/American_Fuzzy_Lop_(software)
At one point it was considered state-of-the-art. As a project it's since been superseded by AFL++ - https://aflplus.plus/ https://aflplus.plus/ .
- daniellionel 1mo agovery cool! will check that out. (hi, author here)
- idoubtit 1mo agoI'm sorry, but I can't understand how AFL++ could be applied to the Gleam case. The main presentation of the tool lacks any description of its coverage, but from deep inside the documentation[^1] I gather that AFL++ is only relevant for GCC/LLVM languages. Gleam is not one of those. [^1]: https://github.com/AFLplusplus/AFLplusplus/blob/stable/docs/fuzzing_in_depth.md#a-selecting-the-best-afl-compiler-for-instrumenting-the-target https://github.com/AFLplusplus/AFLplusplus/blob/stable/docs/...
- WalterGR 1mo agoAh, thanks for the correction. I was under the impression that AFL (I don't know much about AFL++) could instrument arbitrary binaries (with obvious limitations like requiring a known calling convention.)