CVE-2014-1824 – A New Windows Fuzzing Target
blog.beyondtrust.com
blog.beyondtrust.com
If you are writing a blog post and have no ideas for the introduction, please just skip it rather than crowbarring in an awkward reference to other items in the news.
Seriously, one step of the method is “look at every snippet of code that was not visited by the analyzer and explain why it wasn't visited”. One particular usage of a multi-purpose library may always leave you with seemingly unreachable code (that is in fact only useful for other usages of the library), so the presence of such unreachable code cannot be considered a bug, but verifying a library in the way one usage of PolarSSL was verified means each instance of unreachable code is justified.
(The “goto fail” bug could have been found in many other ways, and I admit that makes my using it as an introduction slightly tangential, but it is not my job to advertise all these other ways—some of which are already recognized and easy to apply by a company the size of Apple.)
A modified hypervisor that would use the features initially intended for “replay debugging” for measuring coverage instead could be cool, though.