Language Selection

English French German Italian Portuguese Spanish

Fuzz testing with zzuf

Filed under
HowTos

Fuzz testing, which uses random input to test software for bugs, has been the biggest thing to happen in IT security in quite awhile. Now you can quickly and easily direct your own fuzz testing ops, thanks to a cool little program called zzuf.

We can thank stupid users for the fuzz testing craze -- users who enter dates where dollar amounts are supposed to go, or digits where their names belong, or a ZIP code where a Social Security number is expected. Their lameness often results in instant breakage -- segfaults, overruns, all manner of crashes. And some of those crashes are perfect for exploiting, allowing black hats to gain access to systems or data -- like the Wi-Fi vulnerabilities that were almost disclosed at BlackHat about this time last year, for example, which were discovered by fuzz testing the Wi-Fi drivers with unexpected data.

Fuzz testing throws anything and everything, and sometimes nothing at all, at applications expecting data of a certain size, shape, or format. Many programs are more stable and secure today because of the hidden flaws found with fuzz testing.

More Here




More in Tux Machines

[Stable] OpenELEC 8.0.2 released

OpenELEC 8.0.2 release has been published. Users running OpenELEC 8.0.0 or later with auto-update enabled will be prompted on-screen to reboot and apply the update once it has been downloaded and enabled in some hours. Users running older OpenELEC releases or with auto-update disabled will need to manually update. If you would like to update from an older OpenELEC release please read update instructions/advice on the Wiki before updating. Manual update files can be obtained from the downloads page. Read more

Red Hat Financial News

Android Leftovers

Today in Techrights