Posts

Showing posts with the label Application Security

Fuzzing Explained: Finding Bugs with Malformed Input for Security+ and PenTest+

Fuzzing , or fuzz testing, is the practice of throwing large volumes of malformed, unexpected, or random input at a program to see what breaks. It is deliberately unsubtle, and it works. Fuzzing finds the bugs nobody thought to test for, because it does not know what the program expects and does not care. A human tester writes cases for the scenarios they can imagine. A fuzzer generates millions of cases nobody imagined — a length field claiming four billion bytes, a filename made of null characters, a JPEG whose header says one thing and whose body says another. Some fraction of those trigger a crash, and a crash in code that parses untrusted input is very often an exploitable vulnerability. How It Works Every fuzzing campaign has the same four parts. The target. Something that accepts input — a file parser, a network service, an API endpoint, a browser, a kernel driver. Anything that takes data from outside and interprets it. The input generator. The engine producing te...