|
Paul Dreik
@
PaulDreik
Stockholm, Sverige
|
|
C++ enthusiast
|
|
|
145
Tweetovi
|
129
Pratim
|
459
Osobe koje vas prate
|
| Tweetovi |
|
Paul Dreik
@PaulDreik
|
28. sij |
|
My talk on crypto is up on YouTube now! Thanks @haralda4z for the video editing 👍 twitter.com/StockholmCpp/s…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
26. sij |
|
I believe it will appear in a few days, follow @StockholmCpp to get the announcement!
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
26. sij |
|
I just published the code for my talk: github.com/pauldreik/rand…
|
||
|
|
||
| Paul Dreik proslijedio/la je tweet | ||
|
StockholmCPP
@StockholmCpp
|
23. sij |
|
"home made crypto" by @PaulDreik pic.twitter.com/JxtHu98uaH
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
29. pro |
|
That might also lead to random order.
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
29. pro |
|
I implemented lazy random iteration through a range, using Fisher-Yates shuffling combined with sparse storage:
pauldreik.blogspot.com/2019/12/iterat…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
18. pro |
|
Don't roll your own crypto, they say. Well, it can be pretty useful! Come listen to my talk in the mine at Jan 23:rd if you are interested.
gettogether.community/events/3579/0x…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
10. pro |
|
Sounds like a perfect thing for cppcheck to find!
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
9. pro |
|
Yep, that was me 😀
youtube.com/watch?v=e_Oc9S…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
8. pro |
|
You are very welcome! That means we have at least two attendees!
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
8. pro |
|
Shoutout to programmers in Sweden:
Is there any interest in arranging a #fuzzing meetup?
There is one in the Bay area, far far away...
Please RT for reach.
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
8. pro |
|
By luck, I discovered the awesome libdivide.com through this blog post: lemire.me/blog/2019/02/0… by @lemire. I have now contributed a fuzzer and have programmed with simd intrinsics for the first time!
github.com/ridiculousfish…
|
||
|
|
||
| Paul Dreik proslijedio/la je tweet | ||
|
Victor (vitaut) Zverovich
@vzverovich
|
24. stu |
|
Thanks to @PaulDreik {fmt} now has a shiny new oss-fuzz badge and the first short-lived regression found by fuzzer has been fixed! #fuzzing #ossfuzz pic.twitter.com/v4oGQkBCfu
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
14. stu |
|
Ser this one: guidovranken.com/2019/05/14/dif…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
14. stu |
|
Libfmt for fuzzing templated libs. Curl for fuzzing networked stuff.differential fuzzing for finding crypto flaws. Tnef for an ugly fuzzing hack,finding a cve. Afl jpeg creation to be impressed.
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
14. stu |
|
What is the purpose of the example? Teaching? Demonstration?
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
13. stu |
|
Have you ever got one of those winmail.dat emails, and used the tnef tool to unpack it?
I did and felt a bit uneasy, so I fuzzed tnef with afl and found CVE-2019-18849.
My fuzzer is here: github.com/pauldreik/tnef…
The security advisory is here: cve.mitre.org/cgi-bin/cvenam…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
9. stu |
|
Out sailing in the Swedish archipelago. Cold but beautiful! pic.twitter.com/M9b5BW8giQ
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
6. stu |
|
I am proud to have found and/or fixed nine of those bugs! Feels great to have contributed to this wonderful project. twitter.com/bagder/status/…
|
||
|
|
||
|
Paul Dreik
@PaulDreik
|
31. lis |
|
That works fine!
|
||
|
|
||