Region: Worldwide excl. Europe   Change Region
Home   |   About Us   |   Contact Us   |  

Home > Hacking and Penetration Testing > Open Source Fuzzing Tools

Open Source Fuzzing Tools

ISBN: 9781597491952
Pages: 210
Trim: 7.5 in x 9.25 in
Publication Date: Dec 2007

Region: Worldwide excl. Europe - $USD
Change Region »

$ 62.95 USD Buy Now

or buy from
Amazon.com
BN.com

Open Source Fuzzing Tools

By Noam Rathaus, Gadi Evron

Description

Fuzzing is often described as a "black box” software testing technique. It works by automatically feeding a program multiple input iterations in an attempt to trigger an internal error indicative of a bug, and potentially crash it. Such program errors and crashes are indicative of the existence of a security vulnerability, which can later be researched and fixed.

Fuzz testing is now making a transition from a hacker-grown tool to a commercial-grade product. There are many different types of applications that can be fuzzed, many different ways they can be fuzzed, and a variety of different problems that can be uncovered. There are also problems that arise during fuzzing; when is enough enough? These issues and many others are fully explored.

. Learn How Fuzzing Finds Vulnerabilities
Eliminate buffer overflows, format strings and other potential flaws
. Find Coverage of Available Fuzzing Tools
Complete coverage of open source and commercial tools and their uses
. Build Your Own Fuzzer
Automate the process of vulnerability research by building your own tools
. Understand How Fuzzing Works within the Development Process
Learn how fuzzing serves as a quality assurance tool for your own and third-party software

About the Authors

Noam Rathaus
Co-founder and CTO, Beyond Security, Israel, Microsoft Events Insider

Gadi Evron
Former Internet Security Operations Manager for the Israeli government, Founder of the Israeli government's Computer Emergency Response Team

Contents

  • Introduction to Software Testing
    Introduction to Vulnerability Research
    Fuzzing, what's that?
    A Bit of History
    Basic Fuzzing Techniques
    Advanced Fuzzing Methodologies and Technologies
    Open Source Solutions
    Commercial Solutions
    Build Your Own Fuzzer
    Integration of Fuzzing in the Development Cycle
    Testing Third-party Software
    Certification and Regulation