Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 18 Mar 2015 13:35:06 +0100
From: Frank Dittrich <frank.dittrich@...lbox.org>
To: john-dev@...ts.openwall.com
Subject: Re: Extend AFL to fuzz as you want

On 03/18/2015 01:12 PM, Alexander Cherepanov wrote:
> I think this is a general question to be discussed in john-dev, not
> limited by the needs of fuzzing or security in general. Talking
> specifically about fuzzing, when you want to fuzz functions behind the
> valid() it's easier to patch this specific check out of valid() for now.

But isn't the purpose of valid() to make sure all the other format
methods only have to work with sane/sanitized input?
Why should we care about segfaults etc. that would only occur after you
removed some of the sanity checks in valid?

Frank

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.