If it's smart enough to learn how to build a JPEG in a day, use it with netcat and it could probably send quite a lot of things down in flames.
Who needs static analysis :) ?
If it's smart enough to learn how to build a JPEG in a day, use it with netcat and it could probably send quite a lot of things down in flames.
Who needs static analysis :) ?
> it triggers a slightly different internal code path in the tested app
This would be impossible on the network.
Ah yes, I forgot this little detail. I wonder if you can get it to work on the local machine first, but talking throught a socket instead of stdin.
Then, pipe the result throught netcat !
(This isn't a new concept, although afl is a particularly tight implementation of it; you can look up the paper for "autodafe" for a (much) earlier version).
That's got to be the funniest and most appropriate name for a piece of software ever.
I never understood this attitude. It has always been my experience that obscurity is in fact an important part of security. It's a weakness when mistaken for security, not when understood as part of it.
Sadly, I do actually have signatures (with version information) to mute.
I mean remembering, that the net is full of slow brute-forcers and the like. Just because it takes a few days to run through all the exploits doesn't mean that someone won't do it - that's thinking of security in human, individual terms, as though the threat is targeted rather then general.
And if you need your headers to tell you what versions are running and what tools are installed you are doing something else very wrong.