Honggfuzz

Honggfuzz

Google
+
+

Related Products

  • Parasoft
    151 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website
  • Aikido Security
    239 Ratings
    Visit Website
  • Jscrambler
    40 Ratings
    Visit Website
  • QA Wolf
    270 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website
  • Checksum.ai
    1 Rating
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • NMI Payments
    111 Ratings
    Visit Website
  • TraceEngine
    1 Rating
    Visit Website

About

Our platform uses various security techniques, including coverage-guided and feedback-based fuzz testing, to automatically generate millions of test cases that trigger hard-to-find bugs deep within your application. This white-box approach protects against edge cases and speeds up development. Advanced fuzzing engines generate inputs that maximize code coverage. Powerful bug detectors check for errors during code execution. Uncover true vulnerabilities only. Get the input and stack trace as proof, so you can reliably reproduce errors every time. AI white-box testing uses data from all previous test runs to continuously learn the inner-workings of your application, triggering security-critical bugs with increasingly high precision.

About

Honggfuzz is a security-oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW-based). It’s multi-process and multi-threaded, there’s no need to run multiple copies of your fuzzer, as Honggfuzz can unlock the potential of all your available CPU cores with a single running instance. The file corpus is automatically shared and improved between all fuzzed processes. It’s blazingly fast when the persistent fuzzing mode is used. A simple/empty LLVMFuzzerTestOneInput function can be tested with up to 1mo iteration per second on a relatively modern CPU. Has a solid track record of uncovered security bugs, the only (to date) vulnerability in OpenSSL with the critical score mark was discovered by Honggfuzz. As opposed to other fuzzers, it will discover and report hijacked/ignored signals from crashes (intercepted and potentially hidden by a fuzzed program).

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Not Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Supported
Chromebook Not Supported

Audience

Developers interested in an automated application security solution

Audience

Anyone requiring a solution to detect coding errors and security vulnerabilities

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Pricing

Free
Free Version Supported
Free Trial Not Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Training

Documentation Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Company Information

Code Intelligence
Germany
www.code-intelligence.com

Company Information

Google
United States
github.com/google/honggfuzz

Alternatives

go-fuzz

go-fuzz

dvyukov

Alternatives

LibFuzzer

LibFuzzer

LLVM Project
Mayhem

Mayhem

ForAllSecure
LibFuzzer

LibFuzzer

LLVM Project
Atheris

Atheris

Google
Atheris

Atheris

Google
CI Fuzz

CI Fuzz

Code Intelligence
go-fuzz

go-fuzz

dvyukov

Categories

Code Coverage Supported
Fuzz Testing Supported

Categories

Fuzz Testing Supported

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Not Supported
Source Code Analysis Not Supported
Third-Party Tools Integration Not Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Integrations

C Supported
C++ Supported
CircleCI Supported
Cygwin Not Supported
GitHub Supported
GitLab Supported
Go Supported
Google ClusterFuzz Not Supported
Gradle Supported
JUnit Supported
Java Supported
JavaScript Supported
Jenkins Supported
Jira Supported
Kubernetes Supported
NetBSD Not Supported
OpenSSL Not Supported
Travis CI Supported
Visual Basic Supported
Visual Studio Supported

Integrations

C Not Supported
C++ Not Supported
CircleCI Not Supported
Cygwin Supported
GitHub Not Supported
GitLab Not Supported
Go Not Supported
Google ClusterFuzz Supported
Gradle Not Supported
JUnit Not Supported
Java Not Supported
JavaScript Not Supported
Jenkins Not Supported
Jira Not Supported
Kubernetes Not Supported
NetBSD Supported
OpenSSL Supported
Travis CI Not Supported
Visual Basic Not Supported
Visual Studio Not Supported
Claim Code Intelligence and update features and information
Claim Code Intelligence and update features and information
Claim Honggfuzz and update features and information
Claim Honggfuzz and update features and information