Twitter | Pretraživanje | |
Cornelius Aschermann
PhD on Fuzzing and Stuff
126
Tweetovi
113
Pratim
347
Osobe koje vas prate
Tweetovi
Cornelius Aschermann proslijedio/la je tweet
Mattias Meeta 4. velj
Odgovor korisniku/ci @shashj @EliotHiggins
Locating Patriot Batteries through Radar Interference with freely downloadable Satellite data:
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 4. velj
Odgovor korisniku/ci @binarychrysh
fix'd by adding this to .vimrc "w!! writes files with root rights cmap w!! w !sudo tee % > /dev/null
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 31. sij
huge fan of this presentation style: I would love to see tooling to create this kind of presentation/blogpost easily.
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Andrea Fioraldi 30. sij
Happy to announce a new LLVM instrumentation for AFL++ called CmpLog that feeds the fuzzer with comparisons operands extracted with SanCov. I used it to build the Redqueen mutator in AFL++!
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Caroline Lemieux 25. sij
Check out the RLCheck preprint! Cool idea to try and use reinforcement learning to tune generators to generate more valid (assumption-satisfying) inputs. With
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 22. sij
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Sceptic 21. sij
Picked up my badge for . I will be talking about the push for PLC security and how disregarding system components has rendered such efforts fruitless. Join me on Wednesday morning for 's and my take on the pros and cons of allowing low-level PLC access.
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Marcel Böhme 11. sij
AFLNet is a pretty awesome tool for fuzzing network protocols! Our tool paper reports on implementation and strong first results (e.g., CVE-2019-7314). Stay tuned for more improvements and a full-fledged evaluation.
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Dominik 3. sij
The Fuzzing Round Table Video from hosted by and me and featuring and many more. Sorry for the sound, it could be a lot better but is understandable at least.
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Andrea Fioraldi 26. pro
New blogpost: Sanitized Emulation with QEMU-AddressSanitizer I just open-sourced my QEMU patches to fuzz binaries with ASan, QASan. You can also use it with ARM targets on Linux, a thing that you can't do with LLVM ASan!
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Bryan Cantrill 31. pro
If you are a C or C++ programmer somehow still on the fence about whether or not you should take seriously, consider this piece from Cliff Biffle an absolute must-read:
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 27. pro
Anyone at wants to discuss Fuzzing/RE/Program Analysis/anything really, hmu
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 27. pro
Odgovor korisniku/ci @lavados @gannimo
(Tomorrow, 20:00 in M2)
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 27. pro
Odgovor korisniku/ci @gannimo
You'll be at the fuzzing round table, I assume?
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Dominik 26. pro
'Tis the season If you're into fuzzing don't miss the meetup on day 2 at 8pm. See you around :)
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 18. pro
Odgovor korisniku/ci @mhlakhani @metzmanj
We absolutely do! I was working on it some time ago, but it is surprisingly difficult to find a good test set. I personally believe measuring code coverage found on a diverse set of targets is the best approach, others think we actually need to find bugs....
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 18. pro
Odgovor korisniku/ci @feliam @0xadr1an
Undefined behavior is always a bug. No matter what behavior you expect, the compiler can change it without notice. Consider The compiler simply removed security relevant code due to an integer overflow, but only under specific circumstances...
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann 18. pro
Odgovor korisniku/ci @metzmanj @mhlakhani
Also, you always have to mind the nature of academic publishing: Its a lot easier to publish a paper, if the evaluation follows a known path. If you'd base your paper on something else, I would expect, that at least one (less informed) reviewer would take offense.
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Andrea Fioraldi 13. pro
I and are organizing a round table about new directions in at We'll try to not overlap fuzzing talks (we can change the time slot later if the room is available). Join if you're in the fuzzing loop (we'll publish a signup form ASAP)
Reply Retweet Označi sa "sviđa mi se"
Cornelius Aschermann proslijedio/la je tweet
Marcel Böhme 9. pro
"Time Travel Testing for Android apps" accepted at ! Congrats @zhendon01965406, Lucia and Abhik! Preprint and tool will be available soon. 1/4
Reply Retweet Označi sa "sviđa mi se"