TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Looking Back at Three Months of afl-fuzz

76 pointsby hnmcsover 10 years ago

3 comments

skrebbelover 10 years ago
&gt; <i>Since then, afl-fuzz helped to squash hundreds of bugs, in part due to a community of folks who found the tool to be fun to use.</i><p>I wonder whether a tool as unexpectedly successful as this presents the security community with a weird dilemma: If so many people have begun to use afl-fuzz, find problems, and report them, can&#x27;t we expect that just as many people find problems and <i>don&#x27;t report them</i>?<p>Now, my security expertise goes as far as &quot;don&#x27;t roll your own&quot;, so maybe all the bugs found were, in practice, relatively difficult to exploit. But could afl-fuzz have helped scores of blackhatters to find and abuse the next shellshocks? If so, in hindsight, was it actually a good move to release afl-fuzz so openly and enthusiastically?
评论 #8942881 未加载
616cover 10 years ago
The more I have heard of this guy&#x27;s work, the more disturbed I am by his skill, breadth, and depth in InfoSec.<p>Not to mention his insane CNC and robotics work. And that is just a freaking hobby to him.<p><a href="https://duckduckgo.com/html?q=lcamtuf%20cnc" rel="nofollow">https:&#x2F;&#x2F;duckduckgo.com&#x2F;html?q=lcamtuf%20cnc</a>
dantiberianover 10 years ago
I&#x27;d like to see the SQLite SQL statements, are there any links available?
评论 #8942584 未加载