Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fhenneke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Fuzzing JavaScript with open-source tools (live)
(youtube.com)
2 points
by
fhenneke
4y ago
|
0 comments
2.
▲
Fuzzing JavaScript with open-source tools (live stream)
(code-intelligence.com)
3 points
by
fhenneke
4y ago
|
0 comments
3.
▲
Autofuzz – Fuzzing Java Without Writing Fuzz Targets
(fuzz.ci)
3 points
by
fhenneke
5y ago
|
1 comments
4.
▲
by
fhenneke
6y ago
While I agree with most of what you are saying (let's hope that 2021 will finally be "the year of memory-safe languages"), remote code execution issues also affect Java. https://securitylab.github.com/research
5.
▲
by
fhenneke
6y ago
With minor changes to the default exclude list for coverage instrumentation, you can use Jazzer to fuzz the Java standard library (at least the parts that are implemented in Java).
6.
▲
by
fhenneke
6y ago
That depends on the language you want to fuzz. A good general introduction and hands-on "course" for C/C++ is https://github.com/Dor1s/libfuzzer-workshop . If you prefer Java and just want to get a feelin
7.
▲
by
fhenneke
6y ago
One of the authors of Jazzer here. Feel free to ask any questions regarding Jazzer ( https://github.com/CodeIntelligenceTesting/jazzer ) or how to integrate Java/JVM projects into OSS-Fuzz.
8.
▲
Show HN: Chrome 89 Android Autofill improvements
(github.com)
3 points
by
fhenneke
6y ago
|
0 comments
9.
▲
How to instrument JVM bytecode for fuzzing (open-source)
(blog.code-intelligence.com)
14 points
by
fhenneke
6y ago
|
1 comments
10.
▲
by
fhenneke
6y ago
The FuzzedDataProvider (docs at https://codeintelligencetesting.github.io/jazzer-api/com/cod... ) offers many of the functions you would need to write such a generator. If there is something missing that could be g
11.
▲
by
fhenneke
6y ago
Thanks for the link, I wasn't aware of this new feature! Our coverage instrumentation does not rely on JNI calls, only the libFuzzer callbacks do, so the overhead shouldn't be too substantial. It's certainly not a proper benc
12.
▲
by
fhenneke
6y ago
If you want to fuzz a Java web app, our commercial platform CI Fuzz (of which Jazzer is one part) has built-in detectors for the typical vulnerabilities such as SQL injections: https://blog.code-intelligence.com/sql-fuzzing
13.
▲
by
fhenneke
6y ago
Good catch, thanks ;-) I will update the post.
14.
▲
by
fhenneke
6y ago
By default, uncaught exceptions and memory issues in JNI libraries are reported as "crashes". Additionally, Jazzer provides a hooking framework that can be used to implement domain-specific sanitizers for logic bugs. See https:&#
15.
▲
by
fhenneke
6y ago
I'm one of the engineers behind Jazzer and happy to answer any questions about it. We also have a blogpost that talks about the most interesting technical aspects of Jazzer: https://blog.code-intelligence.com/engineerin
16.
▲
by
fhenneke
6y ago
Yes, that is exactly how it works, there is nothing that would require source code access. If you have a Java app packaged as app.jar, all you need to do is write a fuzz target (with the fuzzerTestOneInput function) and package it into e.g.
17.
▲
by
fhenneke
6y ago
I'm one of the engineers behind Jazzer and happy to answer any questions about it. We also have a blogpost that talks about the most interesting technical aspects of Jazzer: https://blog.code-intelligence.com/engineerin
18.
▲
by
fhenneke
6y ago
The tokens are engineered to protect the private key material stored inside them very well, so you can be quite certain that nobody will ever be able to log in without physical access to the key (to touch/press the button). However, th
19.
▲
by
fhenneke
6y ago
You can set a FIDO2 PIN on your security key and it will prevent ssh-keygen/ssh-add from regenerating the key files without it. But the relevant information (the key handle) can also be retrieved from the key in other ways that don
20.
▲
by
fhenneke
6y ago
The new OpenSSH keys are very convenient if used correctly, but have a crucial disadvantage compared to the PIV-based approach of yubikey-agent: They currently can't be protected effectively with a PIN, so you should take good care of
21.
▲
What’s New in YubiKey Firmware 5.2.3
(yubico.com)
2 points
by
fhenneke
7y ago
|
1 comments
22.
▲
Show HN: Self-decrypting HTML files with WebCrypto
(github.com)
1 points
by
fhenneke
8y ago
|
0 comments
23.
▲
by
fhenneke
8y ago
You can use Secure Shell for SSH with your Yubikey in the meantime: https://chromium.googlesource.com/apps/libapps/+/HEAD/nassh/...
24.
▲
by
fhenneke
9y ago
A Bloom filter with >500M items, even when allowing for a comparatively high rate of false positives such as 1 in 100, is still in the hundreds of MBs, which would not be that much more accessible than the actual dump files.