4 ms·
I'm sure you have checked out the official documentation (http://lcamtuf.coredump.cx/afl/README.txt http://lcamtuf.coredump.cx/afl/README.txt)? Fuzzing Python
by kkl 11y ago
I'm sure you have checked out the official documentation (http://lcamtuf.coredump.cx/afl/README.txt http://lcamtuf.coredump.cx/afl/README.txt)?
Fuzzing Python programs with AFL will be hard. AFL leverages a version of the GCC compiler to instrument (add additional code to) the resultant binaries. Because Python is not a compiled language this will be difficult. I'm sure there is something you could do to make it work.
- StavrosK 11y agoI did read the docs, and that's the conclusion I arrived at as well. I assumed there would be a layer that generated the inputs and checked the outputs, and that I could just use that, rather than use the full code checks, but it looks like that's not the case.
- gsnedders 11y agoThere's a wrapper for CPython to get it to implement the tracing code, afl-python[1]. Alex Gaynor did a basic intro to it a few days ago which is a better write-up that the project itself has! Of course, this doesn't work so well with mixed C/Python code. [1]: https://bitbucket.org/jwilk/python-afl https://bitbucket.org/jwilk/python-afl [2]: https://alexgaynor.net/2015/apr/13/introduction-to-fuzzing-in-python-with-afl/ https://alexgaynor.net/2015/apr/13/introduction-to-fuzzing-i...