SlowFuzz: a spin on libFuzzer so as to favor inputs incurring a slowdown.
2.9K
https://hub.docker.com/r/zjuchenyuan/slowfuzz
Source: https://github.com/nettrino/slowfuzz
Version: e124345
Last Update: 2017/11
Type: libfuzzer-based
Tag: Algorithm complexity
It's not trivial to write code for using SlowFuzz, here is an example:
https://github.com/nettrino/slowfuzz/tree/master/apps/isort
docker run --rm -w /slowfuzz/apps/isort -v `pwd`/output/slowfuzz:/slowfuzz/apps/isort/out2 --privileged zjuchenyuan/slowfuzz \
sh -c "make test && cp out/* out2/"
The output files can be found here.
CCS 2017: SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity Vulnerabilities PDF, ACM Page
Content type
Image
Digest
Size
529.5 MB
Last updated
about 7 years ago
docker pull zjuchenyuan/slowfuzz