The #AFL #fuzzer was able to generate a valid JPEG file by doing coverage-sensitive fuzzing on a JPEG parser (djpeg) for six hours, surprising even its author #lcamtuf. “You can throw afl-fuzz at many other types of parsers with similar results: with bash, it will write valid scripts; with giflib, it will make GIFs; with fileutils, it will create and flag ELF files, Atari 68xxx executables, x86 boot sectors, and UTF-8 with BOM. In almost all cases, the performance impact of instrumentation is minimal, too.”
Somebody’s fuzzing the Linux kernel with #AFL and #QEMU to find #security problems. Gets reasonable performance by forking QEMU repeatedly from a sort of checkpoint just after the kernel within has booted.
on 02016-08-02Dan Luu brings his hardware background to software testing and suggests combining a QuickCheck-like random test generation approach with the #coverage #testing used by the #afl fuzzer. #fuzzing #testing
on 02016-01-14Michał Zalewski (#lcamtuf) very quickly found crash bugs in #SQLite with #afl.
on 02015-08-13