@LiveOverflow
  @LiveOverflow
LiveOverflow | How Fuzzing with AFL works! | Ep. 02 @LiveOverflow | Uploaded 3 years ago | Updated 9 hours ago
Let's investigate some issues we have fuzzing sudo with afl. And also explain how AFL works. After improving our fuzzing setup even more, we are finally read to start fuzzing sudo for real. Can we find the vulnerability now?

liveoverflow.com/support

Grab the files: github.com/LiveOverflow/pwnedit
milek7's blog: https://milek7.pl/howlongsudofuzz/

Sudo Research Episode 02:
00:00 - Recap
00:39 - Fixing AFL Crash Using LLVM mode
03:32 - Testing the AFL Instrumented Sudo Binary
04:11 - How Fuzzing with AFL works!
06:44 - Can AFL find the crash?
08:06 - Detour: busybox and argv[0]
09:48 - How could we discover "sudoedit"?
10:47 - Can AFL find "sudoedit" through magic?
11:25 - Include argv[0] in the testcases
13:06 - Parallel Fuzzing Setup

-=[ ❤️ Support ]=-

→ per Video: patreon.com/join/liveoverflow
→ per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ 🐕 Social ]=-

→ Twitter: twitter.com/LiveOverflow
→ Website: liveoverflow.com
→ Subreddit: reddit.com/r/LiveOverflow
→ Facebook: facebook.com/LiveOverflow
How Fuzzing with AFL works! | Ep. 02My theory on how the webp 0day was discovered #shortFuzzing Heap Layout to Overflow Function Pointers | Ep. 11Reversing Statically-Linked Binaries with Function Signatures - bin 0x2DAttacking Language Server JSON RPCHow Hacking Actually Looks Like - ALLES! CTF Team in Real TimeFinding Buffer Overflow with Fuzzing | Ep. 04Google Paid Me to Talk About a Security Issue!Awkward VLOG at Nullcon Berlin 2022New Challenges Released for CSCG 2021 (including mine) #shortsI Spent 100 Days Hacking MinecraftHacker Culture Meritocracy?

How Fuzzing with AFL works! | Ep. 02 @LiveOverflow

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER