Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 7 Apr 2015 13:27:40 -0700
From: Michal Zalewski <>
To: oss-security <>
Subject: Re: Hanno Boeck found Heartbleed using afl + ASan!

You know... on some level, I'm happy - but on another, I'm always
trying to be skeptical when such claims are made for other projects.
It's only fair not to treat this case differently.

It's worth remembering that the authors of several static analysis or
symbolic execution frameworks have also claimed that their products
would have found Heartbleed. IIRC, their experiments were far more
convoluted than Hanno's, but the bottom line is that when you're
trying to "discover" a bug you already know about, it's almost
impossible to avoid subconsciously optimizing for the expected

So, I always urge people to ask a simple question: would someone think
of running the tool this particular way and on this particular code
before we knew about the bug? And if yes, why haven't they?=)

The answer I've always heard from commercial software vendors is that
"they had no time to work on open source projects", but that's about
as unconvincing as it gets. I bet they would love to be credited for
this or any comparably serious find. Today, I'm asking myself the same
question about AFL. Was it too counterintuitive to set this up? Were
there other barriers to entry? Can I fix this now?


On Tue, Apr 7, 2015 at 1:00 PM, David A. Wheeler <> wrote:
> FYI:
> Hanno Boeck found Heartbleed using american fuzzy lop combined with Address Sanitizer (ASan):
> I've posted a few additional comments here:
> --- David A. Wheeler

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.