awesome-fuzzing
by cpuu
A curated list of awesome Fuzzing(or Fuzz Testing) for software security
AI summary
Vulnerability finder
A curated list of resources and tools for testing software security by providing invalid or unexpected inputs to identify vulnerabilities.
- stars
- 853
- forks
- 86
- watching
- 47
- awesome lists
- 4
- entries
- 181
What's in the list
181 links in 14 sections, with live GitHub stats.activeno commit in 2y
Books
- The Fuzzing Book
(2019)
- The Art, Science, and Engineering of Fuzzing: A Survey
(2019) - Actually, this document is a paper, but it contains more important and essential content than any other book
Talks
- Fuzzing Labs - Patrick Ventuzelo
, Youtube
- Effective File Format Fuzzing
, Black Hat Europe 2016
- Adventures in Fuzzing
, NYU Talk 2018
- Fuzzing with AFL
, NDC Conferences 2018
Papers / The Network and Distributed System Security Symposium (NDSS)
Papers / IEEE Symposium on Security and Privacy (IEEE S&P)
Papers / USENIX Security
Papers / ACM Conference on Computer and Communications Security (ACM CCS)
Papers / ArXiv (Fuzzing with Artificial Intelligence & Machine Learning)
Papers / The others
Tools / File
AFL++
AFL++ is a superior fork to Google's AFL - more speed, more and better mutations, more and better instrumentation, custom module support, etc
Angora
Angora is a mutation-based coverage guided fuzzer. The main goal of Angora is to increase branch coverage by solving path constraints without symbolic execution
Tools / API
- IvySyn
IvySyn is a fully-automated framework for discovering memory error vulnerabilities in Deep Learning (DL) frameworks
MINER
MINER is a REST API fuzzer that utilizes three data-driven designs working together to guide the sequence generation, improve the request generation quality, and capture the unique errors caused by incorrect parameter usage
RestTestGen
RestTestGen is a robust tool and framework designed for automated black-box testing of RESTful web APIs
GraphFuzz
GraphFuzz is an experimental framework for building structure-aware, library API fuzzers
Minerva
Minerva is a browser fuzzer augmented by API mod-ref relations, aiming to synthesize highly-relevant browser API invocations in each test case
FANS
FANS is a fuzzing tool for fuzzing Android native system services. It contains four components: interface collector, interface model extractor, dependency inferer, and fuzzer engine
Tools / CPU
DifuzzRTL
DifuzzRTL is a differential fuzz testing approach for CPU verification
MorFuzz
MorFuzz is a generic RISC-V processor fuzzing framework that can efficiently detect software triggerable functional bugs
SpecFuzz
SpecFuzz is a tool to enable fuzzing for Spectre vulnerabilities
Transynther
Transynther automatically generates and tests building blocks for Meltdown attacks with various faults and microcode assists
Tools / Web
TEFuzz
TEFuzz is a tailored fuzzing-based framework to facilitate the detection and exploitation of template escape bugs
Witcher
Witcher is a web application fuzzer that utilizes mutational fuzzing to explore web applications and fault escalation to detect command and SQL injection vulnerabilities
CorbFuzz
CorbFuzz is a state-aware fuzzer for generating as much reponses from a web application as possible without need of setting up database, etc
Tools / Blockchain
Tools / DBMS
Squirrel
Squirrel is a fuzzer for database managment systems (DBMSs)
Nothing in this list matches your filter.
Featured in 4 awesome lists
Each link jumps to the spot where the list mentions awesome-fuzzing.