Andrey Fedotov · @anfedotoff
64 followers · 106 posts · Server infosec.exchange

The found solution is pretty simple:
1. Do fuzzing your project with (go-fuzz)
2. Collect coverage using go-fuzz -dumpcover using corpus from 1
3. Use this trick: sed -i '/0.0,1.1/d' coverprofile
4. Create html report: go tool cover -html=coverprofile
5. Enjoy

#go #libfuzzer #fuzzing

Last updated 3 years ago

Andrey Fedotov · @anfedotoff
63 followers · 105 posts · Server infosec.exchange

Does anyone know a convenient approach to get html code coverage report after fuzzing project with (go-fuzz)?
I found this project: github.com/confluentinc/bincov
Looks good, but maybe we have something more?

#go #libfuzzer #fuzzing

Last updated 3 years ago

:verified: domenuk · @dmnk
887 followers · 390 posts · Server infosec.exchange

WRT depreciation: the official alternative uses out-of-process fuzzing, which means the fuzzer doesn't run in the same process as the target.

This is what afl does, as well. It turns out that this doesn't scale well, thanks to IPC overhead and context switches for _every single _ testcase (of which you can reach millions per second of).

We spent years creating good in-process fuzzing with , trying to match the success of libfuzzer, and it's sad to see the OG in-process fuzzer get depreciated in favour of an (IMHO) technically inferior alternative.

This may be a good engineering choice if you don't care about CPU cost and have an almost infinite amount of CPUs to spare.

The amount of companies worldwide that has a virtually infinite amount of CPU cores to spare for is low.

There are multiple ways to bring fuzzing to the masses, but this is not the one I would pick.

#libfuzzer #libafl #fuzzing

Last updated 3 years ago

Advanced Fuzzing League · @aflplusplus
345 followers · 11 posts · Server infosec.exchange

The depreciation of is a great time to recompile your fuzzing testcases with AFL++'s afl-cc (supports the same testcases!)
and switch your future fuzzer developments to

llvm.org/docs/LibFuzzer.html#s

#libfuzzer #libafl #fuzzing #fuzzingtips

Last updated 3 years ago

hardik05 · @hardik05
90 followers · 8 posts · Server infosec.exchange
hardik05 · @hardik05
90 followers · 8 posts · Server infosec.exchange

Let’s replicate latest vulnerabilities with the provided test cases and then find one using

youtu.be/vhTuXph1dtY

#openssl #libfuzzer #video #SpookySSL

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Google launches FuzzBench service to benchmark fuzzing tools - Google has announced FuzzBench, a free service “for painlessly evaluating fuzzers in a reproducibl... more: nakedsecurity.sophos.com/2020/ -fuzz

#afl #qsym #google #fuzzing #fuzzers #oss #eclipser #libfuzzer #honggfuzz #fuzzbench #securitythreats

Last updated 6 years ago