The Day I Fell in Love with Fuzzing

The Day I Fell in Love with Fuzzing

Assuming you’ve got the necessary tools installed (make, gcc, afl), here’s how easy it is to start fuzzing binitools:

The utility takes INI as input and produces BINI as output, so it’s far more interesting to fuzz than its inverse, . Once I combed out all the fuzzer-discovered bugs, and I agreed with the parser on how all the various edge cases should be handled, I turned the fuzzer’s corpus into a test suite — though not directly. Have a look at all the wacky inputs invented by the fuzzer starting from my single, minimal input:

This essentially locks down the parser, and the test suite ensures a particular build behaves in a very specific way.

Source: nullprogram.com