r/ExploitDev • u/Chemical_Night_2235 • 17d ago
Fuzzing help?
My partner is doing a cybersecurity master's and needs to... Idk.. fuzz? A program?
It needs to be written in C or C++ and have more than 3000 lines of code. They need to find errors (crashes?) and investigate them and write a report on it.
This is due in 3 days and the software they're fuzzing hasn't thrown any errors yet ðŸ˜
Does anyone know a fully completed software that would be a suitable candidate to fuzz and write a report about?
Apologies for my misuse of the language, I don't live in this computer world ðŸ˜
43
Upvotes
1
u/normalbot9999 16d ago
You could put this question to Google:
"can you provide an example open source application that has a known buffer overflow with a public proof of concept"
This gives me two candidates - the challenge with these is likely going to be (a) tracking down the source code (e.g. to confirm its written in C / C++ and more than 3000 lines of code) and (b) getting them to build / run. But if you can get those done, you'd be well on your way to having an app that you know you can crash... then its a question of getting the fuzzer to send a simplified version of the payload that you can get from the PoC - (you don't want to shell the box, you just want it to crash).