What's the best tutorial for fuzzing? Or should I pick some tool and focus on that and then extend from there? Something else? (We are mostly building embedded devices, mostly C and C++)
What's the best tutorial for fuzzing? Or should I pick some tool and focus on that and then extend from there? Something else? (We are mostly building embedded devices, mostly C and C++)
Note that for coverage-guided fuzzing you need a custom C/C++ build with some kind of coverage-tracking active.
libFuzzer is more suited to fuzzing a single method, while AFL gives you a little more freedom when deciding how to fuzz your code.
This is a nice initial look at libFuzzer: https://github.com/google/fuzzer-test-suite/blob/master/tuto...
And here are a couple of my favourite AFL tutorials:
- https://fuzzing-project.org/tutorial3.html
- https://github.com/ThalesIgnite/afl-training
Happy to answer any questions!