How Heartbleed could've been found
blog.hboeck.de
blog.hboeck.de
I'm the author of AFL. I think this is pretty cool, but also would like to ask you all to hold on to your hats =) Here's the short response I posted to the oss-security mailing list:
He is doing great work to make the Internet safer.
[0] http://research.microsoft.com/en-us/um/people/pg/public_psfi...
This seems to me a bit like when you do a maze starting from the finish and it is, for whatever reason, trivial to go from one end to the other.
It is neat that it is 2015 and fuzzers are cool again, though.
Fuzzing "blind" will work...but you will miss a lot without more instrumentation than that.
And the best of it: only Heartbleed. nothing else. Nothing more.
Looks like it really went that way, but what are the odds?
By fuzzing various file inputs I recently found two issues in OpenSSL, but both had been found by Brian Carpenter before, who at the same time was also fuzzing OpenSSL.
But beyond dynamic analysis, someone wrote a static analysis feature to find heartbleed as well: https://github.com/awruef/find-heartbleed
I was inspired to write my own checker to demonstrate how easy it was to my software team.
And when I get a chance I'll try to contribute some general-purpose checkers to clang.
I dunno if it will work, but IMO it matters. If for no other reason than inspiring other folks!
That's not nothing. How many remotely exploitable bugs of massive severity have come from unsafe memory?
Sure, there's much more work to do beyond memory safety, but there isn't much excuse for that one anymore.
[1] http://clipperhouse.com/2015/04/04/liquidity-open-source-and...
Tools are either made by expensive humans, or forged by the Dark Lord Sauron in the fires of Mount Doom.
There's also the matter of who will run those tools. It's not like fuzzers output exploit.sh or something.
Automation and tooling are great, but they aren't replacements for human ingenuity.
So, yeah, fuzzing could find that but it seems like wild overkill. The normal sort of manual range checking one does when implementing a protocol would of worked too...
http://security.coverity.com/blog/2014/Apr/on-detecting-hear...