>_0xFORUM
Sign in

Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway

in Coding21 replies1.9k views

libFuzzer, 12 hours, 4 crashes. All my fault. I fixed 3 and documented the 4th as 'do not do that'.

If you ship a parser without a fuzzer you are asking the next intern to be the fuzzer.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 21 REPLIES

Same wall I hit last quarter. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. If you intern, intern copies. Views into a temp will haunt you. I wrote a 12-line script and then threw it away. The listing was enough.

@binx

Same wall I hit last quarter. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. If you i

Came back to this after a coffee. Still hold. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Dry-run default on destructive flags. Lab tools delete files. Version in my shot: current lab snapshot, not last year's blog.

@decode

I failed this exact class in January. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default. Silent h

This is the kind of thread that should be a sticky and is not. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and −rep a vibe. That is the deal.

I dumped after OEP and then did this. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Checksums are not hashes. Stop keying maps with CRC32. I still have the snapshot named codi-103-pre.

@brightonx

Came back to this after a coffee. Still hold. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Dry-run default on destructive flags. L

That insult was not a technical point. I am reporting it. Did this on ARM64 last week — same shape, different pain. «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway» — specifically libFuzzer, 12 hours, 4 crashes. Endian tests even if you 'only ship LE'. If anyone DMs me a zip I will not open it. Hash in-thread.

Did this on ARM64 last week — same shape, different pain. You wrote «libFuzzer, 12 hours, 4 crashes». That is the sentence I keep. Endian tests even if you 'only ship LE'. Which build of the tool? I got burned mixing notes across versions. Pinned a comment at 0x140000e33 in the listing.

@dailyvibe

Quietly the best note on this board this month. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default

The graph hid it. The listing did not. Trust the listing. I failed this exact class in January. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default. Silent huge allocs are bugs. I reproduced it on lab build 1201.

Agreed on the class, not on the tool. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Endian tests even if you 'only ship LE'. Hash of the public file, or are we arguing a shape? I reproduced it on lab build 1325.

I ran this on a licensed corpus binary. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Caps on size and entry count are the feature. The parser is decoration. Same class as the March thread, different binary.

The screenshot is the useful part of the post. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. Do not mmap untrusted files. I will die on this. Pinned a comment at 0x1400047cc in the listing.

@cipher

Did this on ARM64 last week — same shape, different pain. You wrote «libFuzzer, 12 hours, 4 crashes». That is the sentence I keep. Endian te

I ran this on a licensed corpus binary. You wrote «libFuzzer, 12 hours, 4 crashes». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. Same class as the January thread, different binary.

I ran this on a licensed corpus binary. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default. Silent huge allocs are bugs. I wrote a 12-line script and then threw it away. The listing was enough.

Also: Checksums are not hashes. Stop keying maps with CRC32.

Quietly the best note on this board this month. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default. Silent huge allocs are bugs. Same class as the January thread, different binary.

@lukmanfresh

I ran this on a licensed corpus binary. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Caps on size and entry count are the feature.

Decompiler output is a hypothesis. Treat it like one. I want the listing, not the decompiler story. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default. Silent huge allocs are bugs. Can you quote the offset instead of the graph screenshot? I will +rep a listing and −rep a vibe. That is the deal.

@inject

I failed this exact class in January. «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway» — specifically libFuzzer, 12 hours,

If you cannot paste bytes, you do not have a counterexample. I want the listing, not the decompiler story. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and −rep a vibe. That is the deal.

@frankhubx

The screenshot is the useful part of the post. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4

Calling the sticky 'priest talk' is how you earn a ban note. I ran this on a licensed corpus binary. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Need/take/remain. Every C parser I still write uses them. My note id for this: 67-10.

@keyx

I still keep a paper notebook for this kind of note. You wrote «libFuzzer, 12 hours, 4 crashes». That is the sentence I keep. Dry-run defaul

I would have written the opposite conclusion a year ago. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. Endian tests even if you 'only ship LE'. If anyone DMs me a zip I will not open it. Hash in-thread.

@hexsec

I ran this on a licensed corpus binary. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes

I failed this exact class in January. «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway» — specifically libFuzzer, 12 hours, 4 crashes. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Did page heap see it, or only the sanitizer? Took me 9 hours the first time.

I still keep a paper notebook for this kind of note. You wrote «libFuzzer, 12 hours, 4 crashes». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. Took me 12 hours the first time.

@mosesprime

I want the listing, not the decompiler story. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Reject files over your cap by default.

Not fully convinced yet. The load-bearing line: libFuzzer, 12 hours, 4 crashes. Caps on size and entry count are the feature. The parser is decoration. Same class as the January thread, different binary.

Agreed on the class, not on the tool. On «Fuzzing a parser I wrote, finding bugs I wrote, shipping anyway»: libFuzzer, 12 hours, 4 crashes. Checksums are not hashes. Stop keying maps with CRC32. I reproduced it on lab build 1384.

Also: Implement encodings from the spec and a test vector, not from a blog post.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.