oss-sec mailing list archives

Re: Re: Fuzzing objdump (PR 17512) and readelf (PR 17531)


From: Hanno Böck <hanno () hboeck de>
Date: Fri, 7 Nov 2014 11:59:06 +0100

Am Fri, 07 Nov 2014 13:08:09 +0300
schrieb Yury Gribov <y.gribov () samsung com>:

This looks rather impressive.  Have you considered automatically 
detecting duplicates by e.g. analyzing stacktraces?

american-fuzzy-lop kind of does that. It creates a hash among the code
path and groups fuzzing samples by that. That's quite convenient.

I am currently playing a lot with this. afl is in a somewhat
experimental state and you'll run into more problems trying to get it
running, but if it runs it is much more convenient than zzuf.
Disadvantage is you need to recompile stuff to work with it and that
sometimes fails, esp. when assembler is involved.

-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: