The #AFL #fuzzer was able to generate a valid JPEG file by doing coverage-sensitive fuzzing on a JPEG parser (djpeg) for six hours, surprising even its author #lcamtuf. “You can throw afl-fuzz at many other types of parsers with similar results: with bash, it will write valid scripts; with giflib, it will make GIFs; with fileutils, it will create and flag ELF files, Atari 68xxx executables, x86 boot sectors, and UTF-8 with BOM. In almost all cases, the performance impact of instrumentation is minimal, too.”
#video on "Antithesis", a whole-system #fuzzer using #virtualization to make distributed-system failures reproducible. “But the crazy thing is once I have a time machine, once I have a hypervisor, I can run until I make event A happen. And then if I notice that event A has happened, I can say this is interesting. I want to now just focus on worlds where event A has happened. I don’t need to refind event A every single time. I can just lock it in, right? It’s like if you play computer games, it’s like save scumming, right? It’s like I can I can just save my state when I got the boss down to half health and now always reload from that point.”