We implemented the rule engine in our eBPF-based security monitoring agent Bombini: https://t.co/kD80avQzAe
Rule evaluation is blazingly fast and works entirely in eBPF!
Check out the docs: https://t.co/TCA8M1U6OB
Contributions are welcome!
#ebpf#security#Kubernetes
🐝New Cilium Contributor🐝
The newest Cilium contributor is @anfedotoff
They helped add support for user mode stack traces in events.
https://t.co/ACIFlXGQPS
The blog post about the libwebp vulnerability fuzzing is up, it explains how I set up the experiment, how the crash was found and why oss-fuzz was not able to find it: https://t.co/wuwK2Vj6VO #fuzzing@metzmanj
@domenuk@mihaimaruseac@GuidoVranken For some targets concolic execution can provide fuzzing performance increase. For other targets you could get no effect, or even performance downgrade. I consider symbolic as some kind of "clever mutator", that sometimes might be useful.
Almost a year after my defense, my PhD thesis "Automated Security Testing of Unexplored Targets Through Feedback-Guided Fuzzing" is now archived on the university server 🎉
We fuzzed Nvidia drivers, tcp servers, basebands, WebAssembly, ..
Enjoy reading :)
https://t.co/aBHy2X74iP
https://t.co/uPqN39esnI
#casr 2.6.0, what's new:
casr-libfuzzer tool for triaging crashes found by libFuzzer based fuzzers (C/C++/go-fuzz/Atheris)
kodama crate for clustering instead of python scipy
RISCV support
#fuzzing
Spice up your binary program analysis with TritonDSE !
A blog post by Christian Heitman and @RobinDavid1 introducing our framework for Dynamic Symbolic Execution in Python
#symexec#fuzzing#opensource
https://t.co/fay9SlKee7
I wish tutorial articles would all have a date when they got published and last updated. Followed a tutorial which was not working, spent time trying to fix it and then found out the API has been changed in 2017
As it turns out, compilers happily spill the index for indirect jumps through a jump table after bounds checking, creating a TOCTTOU race for arbitrary control-flow hijacking. Check out our @HexHiveEPFL@IEEESSP "WarpAttack" paper: https://t.co/hBYmGqeh0N
casr-libfuzzer: triage crashes in C/C++/Go/Python code found by libFuzzer/Atheris/go-fuzz
casr-libfuzzer -o out -- /fuzz_target
https://t.co/WK4Ewx597O
#casr#fuzzing#libfuzzer#atheris#go#python#cpp
Excited to present new(?) approach to #fuzzing where one doesn't need to write fuzz functions.
Wanna fuzz all binaries on github - no problem.
Just give the fuzzer binaries to test. No false positives & 100% fidelity.
Blender: whole-program fuzzing:
https://t.co/K0ZQw2L1As