Post #1160 137 Jul 7, 2022, 07:05 UTC Fuzzing Image Parsing in Windows, Part Four: More HEIF - https://www.mandiant.com/resources/fuzzing-image-parsing-windows-part-four Google Cloud Blog Fuzzing Image Parsing in Windows, Part Four: More HEIF | Google Cloud Blog
Post #1159 138 Jun 29, 2022, 07:41 UTC Improving Security by Fuzzing the CNCF landscape - https://www.cncf.io/blog/2022/06/28/improving-security-by-fuzzing-the-cncf-landscape/ CNCF Improving Security by Fuzzing the CNCF landscape By Chris Aniszczyk (CNCF), Adam Korczynski (Ada Logics), David Korczynski (Ada Logics) In this blog post we present an overview of the state of fuzzing across CNCF projects. This is based on efforts… 👍 2
Post #1158 106 Jun 27, 2022, 08:01 UTC Introduction to VirtualBox security research https://blog.doyensec.com/2022/04/26/vbox-fuzzing.html Doyensec Introduction to VirtualBox security research This article introduces VirtualBox research and explains how to build a coverage-based fuzzer, focusing on the emulated network device drivers. In the examples below, we explain how to create a harness for the non-default network device driver PCNet. The…
Post #1157 102 Jun 20, 2022, 15:08 UTC Effectiveness and Scalability of Fuzzing Techniques in CI/CD Pipelineshttps://arxiv.org/pdf/2205.14964.pdf
Post #1156 105 Jun 17, 2022, 20:22 UTC https://youtu.be/pUwyjjPxrFc YouTube Offensive Security Operations with Attack Surface Management & Always-On Pen Testing Related Courses: https://www.sans.org/cyber-security-courses/?focus-area=penetration-testing-ethical-hacking Presented by: Chris Dale https://twitter.com/ChrisADale How does Continuous Attack Surface Management help disrupt Nation State hackers and cyber…
Post #1155 92 Jun 17, 2022, 10:12 UTC SnapFuzz: High-Throughput Fuzzing of Network Applications https://srg.doc.ic.ac.uk/files/papers/snapfuzz-issta-22.pdf
Post #1154 98 Jun 7, 2022, 18:49 UTC High Performance Coverage-guided Greybox Fuzzer with Custom JIT Enginehttps://seal9055.com/blog/fuzzing/sfuzz
Post #1153 105 Jun 4, 2022, 16:03 UTC CVE-2022-26134 PoCConfluencehttps://github.com/jbaines-r7/through_the_wire GitHub GitHub - jbaines-r7/through_the_wire: CVE-2022-26134 Proof of Concept CVE-2022-26134 Proof of Concept. Contribute to jbaines-r7/through_the_wire development by creating an account on GitHub.
Post #1152 115 Jun 2, 2022, 20:51 UTC Fuzzing the CNCF Landscape - https://youtu.be/zIyIZxAZLzo YouTube Fuzzing the CNCF Landscape - Adam Korczynski & David Korczynski, Ada Logics Fuzzing the CNCF Landscape - Adam Korczynski & David Korczynski, Ada Logics This talk presents Adam’s and David’s experience with fuzzing more than ten projects in the CNCF landscape over the last year resulting in more than hundred bugs filed and fixed.…
Post #1151 78 May 31, 2022, 19:24 UTC HyperDbg Debugger: State-of-the-art native Windows debugging tool designed for analyzing, fuzzing and reversing - https://github.com/HyperDbg/HyperDbg GitHub GitHub - HyperDbg/HyperDbg: State-of-the-art native debugging tools State-of-the-art native debugging tools. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.
Post #1150 93 May 27, 2022, 22:25 UTC Offensive Windows IPC Internals 3: ALPChttps://csandker.io/2022/05/24/Offensive-Windows-IPC-3-ALPC.html
Post #1149 147 May 27, 2022, 12:19 UTC Running HashiCorp Vault in Production by Dan McTeer.pdf2.6 MB Running HashiCorp Vault in Production by Dan McTeerPM for Password 🔥 2 👍 1
Post #1148 80 May 26, 2022, 05:21 UTC Matryoshka Trap: Recursive MMIO Flaws Lead to VM Escapehttps://qiuhao.org/Matryoshka_Trap.pdf
Post #1147 91 May 13, 2022, 21:23 UTC ClusterFuzzLite - Simple continuous fuzzing that runs in CI.https://github.com/google/clusterfuzzlite GitHub GitHub - google/clusterfuzzlite: ClusterFuzzLite - Simple continuous fuzzing that runs in CI. ClusterFuzzLite - Simple continuous fuzzing that runs in CI. - google/clusterfuzzlite
Post #1146 85 May 12, 2022, 19:53 UTC Earn $200K by fuzzing for a weekend: Part 1 - https://secret.club/2022/05/11/fuzzing-solana.html secret club Earn $200K by fuzzing for a weekend: Part 1 By applying well-known fuzzing techniques to a popular target, I found several bugs that in total yielded over $200K in bounties. In this article I will demonstrate how powerful fuzzing can be when applied to software which has not yet faced sufficient testing.
Post #1145 100 May 3, 2022, 08:46 UTC Looking for Remote Code Execution bugs in the Linux kernel - https://xairy.io/articles/syzkaller-external-network Andrey Konovalov 🔍 Looking for Remote Code Execution bugs in the Linux kernel Using syzkaller to fuzz the Linux kernel network stack externally
Post #1144 88 May 2, 2022, 17:00 UTC Generating Test Suites for GPU Instruction Sets through Mutation and Equivalence Checking - https://fuzzingworkshop.github.io/papers/GPU-Slides.pdf 🔥 1
Post #1143 93 Apr 29, 2022, 11:51 UTC Kubernetes GoatInteractive Kubernetes Security Learning Playgroundhttps://madhuakula.com/kubernetes-goat/ Madhuakula Welcome to Kubernetes Goat | Kubernetes Goat Interactive Kubernetes Security Learning Playground 👍 2
Post #1142 86 Apr 27, 2022, 09:50 UTC OffensiveCon22 - Tamas K Lengyel and Bálint Varga-Perke - Case Studies of Fuzzing with Xen - https://www.youtube.com/watch?v=EFrIfXd3KZQ YouTube OffensiveCon22 - Tamas K Lengyel and Bálint Varga-Perke - Case Studies of Fuzzing with Xen https://www.offensivecon.org/speakers/2022/tamas-k-lengyel-and-b%C3%A1lint-varga-perke.html
Post #1141 65 Apr 27, 2022, 09:50 UTC OffensiveCon22 - Patrick Ventuzelo - Beaconfuzz - https://www.youtube.com/watch?v=nERNZ5mL46Q YouTube OffensiveCon22 - Patrick Ventuzelo - Beaconfuzz Beaconfuzz - A Journey into Ethereum 2.0 Blockchain Fuzzing and Vulnerability Discovery https://www.offensivecon.org/speakers/2022/patrick-ventuzelo.html