CERT Releases Basic Fuzzing Framework
infoLaw passes along this excerpt from Threatpost: "Carnegie Mellon University's Computer Emergency Response Team has released a new fuzzing framework to help identify and eliminate security vulnerabilities from software products. The Basic Fuzzing Framework (BFF) is described as a simplified version of automated dumb fuzzing. It includes a Linux virtual machine that has been optimized for fuzz testing and a set of scripts to implement a software test."
Anything that you write that uses a regex you should beat on with some fuzzing logic, since they can tend to increase in computational time non-linearly, and next thing you know you got a DOS on your hands.
TIP OF THE DAY for you FROM ME
And urgently needed. So far the CMU/CERT software I had a look at was pretty good....
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Sort of like this?
in their whitepaper they referenced my 'axfuzz' tool I wrote years ago and even used a modified version of it in their testing. Hope they didn't judge me on that code, it was a pile of crap that I kept hacking together until it finally worked, with no thought to proper software design.
I.O.U One Sig.
The worst case scenario is talking about worse case scenarios thinking about worse case scenarios and letting them possess you.
The game.
Oh FFS, you couldn't even link to the damn framework?
BFF? What an unfortunate choice of acronyms.
'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
I propose that every website which handles private data (credit, ssn, health, etc) should be integrating these kinds of tools into normal test procedures, both in development and on production mirrored sites.
Hear hear!
I said no... but I missed and it came out yes.