Are you a #rustlang #fuzzing nerd? Would you be able to help with fuzzing librsvg?
https://gitlab.gnome.org/GNOME/librsvg/-/issues/1018 has a bunch of tasks that I'd love for someone to explore.
instead of doing the uni work i was supposed to do i started #fuzzing #nextcloud #apis
you gotta decide what is more fun
In which I continue my series on tools that make my life as a working #programmer easier:
https://cohost.org/daxtens/post/2381021-tools-that-make-my-l
Check out #git grep, that one seems new to a bunch of people.
(#programming #fuzzing #debugging)
#programmer #git #programming #fuzzing #debugging
Tavis Ormandy: Zenbleed https://lock.cmpxchg8b.com/zenbleed.html #hardware #security #fuzzing
I’ve been fuzzing the Linux kernel off and on for a few days now — it’s really fun to uncover bugs! There’s an epic battle going on between the fuzzer and the os: Each had made the other crash several times in different ways.
As of now it’s all tied up!
Syzkaller: 3
Kernel: 3
#fuzzing #linux #syzkaller #hpc
Fuzz Introspector is an open source tool that provides insights and suggestions for improvements on how software projects are being fuzzed. David Korczynski and Adam Korczynski take a look & share recent updates in our latest blog: https://openssf.org/blog/2023/07/20/fuzz-introspector-optimizing-fuzzing-workflows/ #fuzzing
🔥⏲️ Fudge Sunday "Fuzz Jam June" A look at the growing importance of fuzzing in platform engineering
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
The Fuzzing Guide to the Galaxy: An Attempt with Android System Services
https://blog.thalium.re/posts/fuzzing-samsung-system-services/
#mobilesecurity #fuzzing #androidsecurity #infosec
I've been tooting a lot about Unicode weirdness, and the different bad ways that #Go and #Python respectively implement it. Also a toot about #fuzzing. That's because:
Current project is rewriting the gtk-doc "markdown" parser from Python to Go so that I can get @diamond's gotk4 to generate better godocs.
I put "markdown" in quotes because it's pretty dang quirky and doesn't implement things that you'd expect markdown to (_like this_ or *this*), but also has some() @special %things.
People talk about how when doing a big refactor or rewrite, you should write a bazillion tests for the old version, and use those tests for validating the new version.
But not enough folks talk about #fuzzing the new version against the old version.
For real, this is the killer-app of fuzzing that no one is talking about. Like, yeah, security is great, but that's not going to get most average developers to start fuzzing.
Fuzzing the Shield: CVE-2022–24548
https://medium.com/s2wblog/fuzzing-the-shield-cve-2022-24548-96f568980c0
#pentesting #fuzzing #cve #cybersecurity #infosec
Today the AWS "Find and Fix" (F2) security research team released Snapchange, a new open source project to make snapshot-based fuzzing much easier.
#OpenSource #OSSummit #LinuxSecuritySummit #Fuzzing #Linux #KVM
https://aws.amazon.com/blogs/opensource/announcing-snapchange-an-open-source-kvm-backed-snapshot-fuzzing-framework/
#kvm #Linux #fuzzing #linuxsecuritysummit #ossummit #OpenSource
aaand I forgot to add @@ at the end so I wasn't actually #fuzzing anything! that's why we test!
Another thing that @tweedegolf inspired us with is fuzzing of #Rust projects. We’ve now used this to fuzz delta construction and merging when developing ASPA support in Routinator. #RPKI #OpenSource #rustlang #fuzzing #security #RoutingSecurity
https://github.com/NLnetLabs/routinator/pull/847/commits/2c65d949756b3ba72a93baa9795ca30646d1aa2e
#rust #rpki #opensource #rustlang #fuzzing #security #routingsecurity
#CNCF #fuzzing #OpenSource projects for #security and #reliability
https://www.cncf.io/blog/2023/04/18/cncf-fuzzing-open-source-projects-for-security-and-reliability/
#cncf #fuzzing #opensource #security #reliability