Fuzzing Irssi (2017)
irssi.org
irssi.org
What's the best tutorial for fuzzing? Or should I pick some tool and focus on that and then extend from there? Something else? (We are mostly building embedded devices, mostly C and C++)
Note that for coverage-guided fuzzing you need a custom C/C++ build with some kind of coverage-tracking active.
libFuzzer is more suited to fuzzing a single method, while AFL gives you a little more freedom when deciding how to fuzz your code.
This is a nice initial look at libFuzzer: https://github.com/google/fuzzer-test-suite/blob/master/tuto...
And here are a couple of my favourite AFL tutorials:
- https://fuzzing-project.org/tutorial3.html
- https://github.com/ThalesIgnite/afl-training
Happy to answer any questions!
Ninja-edit: didn't comprehend your question fully upon first reading. I didn't chose between them. Back in... 2007-ish? I got handed an irssi config by a buddy, and have tweaked it from there since. No active choice being made between the two. Sorry for the misinterpretation.
I've configured it to my liking. I know its ins and outs. It's unlikely to surprise me. I've also written scripts for it, so it does what I want it to do.
Also: I remember trying Weechat once. I typed "/connect blabla" and it errored out, telling me that I can't connect to arbitrary servers without editing some configuration variable or something like that. That gave me bad vibes. Very bad decision. UX matters.