This ICSE'22 paper brings up a very important point in fuzzer evaluation --- the observation that spending more time in the more destructive, "havoc" mutation stage, can lead to higher observed coverage https://t.co/CylNfKJK9U 1/n
Can't agree more: "A comparison to other fuzzers may be conducted optionally if the authors wish to establish the new fuzzer as the new state-of-the-art. However, note that the observed improvements may be largely due to design and engineering differences (e.g.,Honggfuzz vs AFL)"
I appreciate this work very much. Especially it points out the deterministic problem. IMHO, most of the Evaluations in existing works ignore this, and I even consider this might be a "trick" to get better performance
Results from @Google#FuzzBench: An Open Fuzzer Benchmarking Platform and Service is now published in ESEC/FSE’21 (thanks to the authors - @metzmanj, @lszekeres, @lsim99, @sprabery and me :). Check it out here - https://t.co/DsyQDuxXsG
@thuanpv_@rnatella@issta_conf Hi Pham, I meet a problem with aflsmart, I saw there is a similar issue in https://t.co/zXtPfw8eth, can you explain more about where it goes wrong in that input model file? thank you very much
we are the first and the last team to demonstrate the exploit. Nice work & team. btw, our bug for WD NAS is dead before the match, or we can try to get master of pwn😂 anyway, not bad, thank you all guys🥰
Confirmed! The team of @starlabs_sg, @hi_im_d4rkn3ss, @Puzzorsj & @c3xp1r used a race condition and an OOB read to get root access on the Synology NAS. They close out the contest by earning $20,000 and 2 Master of Pwn points.
MSRC sent an email saying that they will provide a 1-year license for Visual Studio Enterprise subscription for those 2020 MSRC Most Valuable Security Researchers. Very nice of them, thanks :) @msftsecresponse
Success! We kick off #Pwn2Own Tokyo (Live From Toronto) with a successful demonstration from he team of
@starlabs_sg, @hi_im_d4rkn3ss, @Puzzorsj and @c3xp1r. They head off to the disclosure room to provide all the details of their exploit chain. #P2OTokyo
CCS delivers again: three CCS second round papers, all hard rejected with very harsh reviews. All three had person years of improvements added to their previous submissions. I'm not sure what to do with CCS anymore.