SPbCTF Meeting (https://vk.com/spbctf)
Fuzzers are groping around in the dark, trying to generate input that will crash the program. To shed some light on the mystery, AFL tracks where it's managed to get in the code, and libFuzzer peeks into constants within the source code. Artur demonstrated the next level: grammar fuzzers, which can be explained in a special format how to generate valid input for a program. Let's look at writing Peach grammars and its combination with AFL—AFLSmart. Solve problems — https://pwn.spbctf.ru
✄ − − − − − − − − − − − − − − − − − − − − − −
If you liked our materials and found them helpful, please support the community with a donation: https://donate.spbctf.ru
CTF in St. Petersburg (SPbCTF) is an open, independent competitive hacking community based in St. Petersburg. We conduct computer security seminars and training sessions for students and schoolchildren in the city in the format of CTF competitions. We also organize competitions, educational intensives for universities and companies, and host events and master classes at conferences. We post edited recordings of our meetings on YouTube, discuss tasks, and stream for fun.
Read: https://vk.com/spbctf
Ask a question in the chat: https://t.me/spbctf
Subscribe to news: https://t.me/spbctfnews and our https://github.com/SPbCTF
Track the movements of the community mascot: / theblzh2017
Write: [email protected]
0:00 Fuzzing complex input data
7:46 Installing AFLSmart
9:56 Grammars in Peach and AFLSmart
11:08 .pit — XML description of the input grammar
16:53 Where to find data types
21:44 Writing simple grammars
26:44 Testing Peach on our grammar
33:37 Combining Peach with AFL → AFLSmart
35:58 Launching AFLSmart on Binary
40:46 Advanced Grammars