Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
evmunro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
evmunro
2y ago
Great idea to make it just a simple URL change. Reminds me of the youtube download websites. I made a similar CLI tool[0] with the added feature that you can pass `--outline` and it'll omit function bodies (while leaving their signatur
2.
▲
by
evmunro
4y ago
You're right, it's likely that almost nobody is using `fmt.Sprintf` to build SQL queries in production. Templating and `fmt.Sprintf` are essentially the same thing in this context - `Sprintf` just gets the point across in fewer li
3.
▲
by
evmunro
4y ago
This is a great resource on fuzz testing algorithms & internals. I find myself coming back to it occasionally when building new fuzzing techniques at Fuzzbuzz.
4.
▲
The Fuzzing Book
(fuzzingbook.org)
55 points
by
evmunro
4y ago
|
3 comments
5.
▲
by
evmunro
4y ago
OP and Founder of Fuzzbuzz here - let me know if you have any questions about fuzz testing, especially any particularly tricky cases you’ve run into.
6.
▲
Advanced Go Fuzzing Techniques
(blog.fuzzbuzz.io)
3 points
by
evmunro
4y ago
|
1 comments
7.
▲
Writing Effective Go Fuzz Tests
(blog.fuzzbuzz.io)
6 points
by
evmunro
4y ago
|
0 comments
8.
▲
by
evmunro
5y ago
I agree - I took a look at the minimization algorithm[0] and it seems like it loops through a few basic options, with the last one basically normalizing all possible bytes to something readable (like "0"). Part of the issue with t
9.
▲
by
evmunro
5y ago
I noticed that as well - most fuzzers will have a maximum duration or number of iterations they're allowed to attempt when minimizing so as not to starve out actual inputs. It could be that the fuzzer hit that limit, or potentially pri
10.
▲
by
evmunro
8y ago
Thanks for the questions & feedback! Concise docs are really important so this is all super useful. To answer your questions one by one: 1) The BrokenMethods are simple examples of programs that crash on buffer overflows/index out
11.
▲
by
evmunro
8y ago
Sure! Some of the classes of bugs that remain low-hanging fruit for languages like Python include slowness, hangs, panics, race conditions, assert failures, excessive resource consumption and other Denial of Service attacks. Other use cases
12.
▲
by
evmunro
8y ago
Radamsa is awesome! Definitely agree, and one of the goals for Fuzzbuzz is to be able to hot-swap between fuzzing backends without any interface changes (or to use all backends at the same time, to account for differences in findings). re:
13.
▲
by
evmunro
8y ago
Thanks for the link! We've been looking at all the current AFL-like/AFL wrappers for Java as we decide how best to implement Java fuzzing in Fuzzbuzz, and yours looks pretty nice. Definitely going to play around with this :)
14.
▲
by
evmunro
8y ago
Memory security issues have been the main focus of fuzzing, but it's really useful for other use cases as well, such as: slowness/hangs, assert failures, panics, excessive resource consumption and DOS attacks. We've also done
15.
▲
by
evmunro
8y ago
We have! afl.rs[1] is awesome, and seeing as it's found some interesting bugs, I think Rust would be a great addition to Fuzzbuzz. It's on our roadmap. [1] https://github.com/rust-fuzz/afl.rs
16.
▲
by
evmunro
8y ago
Yep, we're definitely going to integrate more automated analysis. As of now we do some rudimentary analysis based off the type of the bug (Heap buffer overflow, UAF), read/write size, and similar metrics, but we'll be adding
17.
▲
by
evmunro
8y ago
Thanks for mentioning us on the issue! I'd love to help get that project up and fuzzing
18.
▲
by
evmunro
8y ago
We actually distribute the fuzzing workload across physical machines, for precisely that reason. Each instance of AFL gets its own kernel & physical core, and we use a staged synchronization algorithm to make sure all of the machines&#x
19.
▲
by
evmunro
8y ago
If you're interested in giving it a go, I could set you up with an OSS plan & some free CPU power - let me know! everest@fuzzbuzz.io
20.
▲
by
evmunro
8y ago
Really interesting to see the desire for ruby support in this thread! It's definitely on our roadmap. Shoot me an email at everest@fuzzbuzz.io and I'll let you know when we launch ruby fuzzing.
21.
▲
by
evmunro
8y ago
They certainly could if their project is large enough! Every widely-used C/C++ project should use OSS-Fuzz, it's an awesome service. We support a couple of languages that OSS-Fuzz doesn't (Go & Python as of now), which is
22.
▲
by
evmunro
8y ago
We're already sort of integrated with GitHub, since you can integrate your projects to automatically pull updates from repositories, so GitHub login is definitely on the roadmap!
23.
▲
by
evmunro
8y ago
Since the type of fuzzing you can do right now on Fuzzbuzz is language-specific, you wouldn't be able to fuzz Javascript code. We are in the process of building a fuzzer for generic web-apps, so watch this space :)
24.
▲
by
evmunro
8y ago
That's a problem that we've been thinking about a lot. The way our fuzzing works right now is that your method consumes an array of bytes, which you can then use to build up arbitrary structures. It's simple, but manages to b
25.
▲
by
evmunro
8y ago
We don't support protocol fuzzing yet, but it's definitely on our roadmap - we wanted to start in an area that we felt was lacking the most, and then move into other types of fuzzing. We do have some novel REST API fuzzing techniq
26.
▲
by
evmunro
8y ago
Ruby is one of the languages on the roadmap, but it's not super high-priority right now, mostly because we haven't seen a lot of interest. If you have a specific project/use case in mind I'd be interested to hear more ab
27.
▲
by
evmunro
8y ago
P.s. Know someone who maintains an open-source project, written in C, C++, Go or Python, that should be fuzzed? Please send an email to oss@fuzzbuzz.io. We’d love to fuzz your code for free on our platform and make the world’s open-source s
28.
▲
Launch HN: Fuzzbuzz (YC W19) – Fuzzing as a Service
171 points
by
evmunro
8y ago
|
81 comments
29.
▲
by
evmunro
8y ago
Either libFuzzer or AFL are your best bet for getting started - they both use very similar algorithms and just differ on execution. libFuzzer is more suited to fuzzing a single method, while AFL gives you a little more freedom when deciding
30.
▲
by
evmunro
8y ago
Fuzzing is super powerful, but can be a bit complicated to set up - that's why I'm working on a fuzzing-as-a-service platform[1] that automates a bunch of the steps described here. If you're interested in trying out fuzzing w
More ›