ToothPicker

ToothPicker

Secure Mobile Networking Lab
+
+

Related Products

  • Parasoft
    151 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website
  • Aikido Security
    239 Ratings
    Visit Website
  • Jscrambler
    40 Ratings
    Visit Website
  • QA Wolf
    270 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website
  • Checksum.ai
    1 Rating
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • NMI Payments
    111 Ratings
    Visit Website
  • TraceEngine
    1 Rating
    Visit Website

About

Our platform uses various security techniques, including coverage-guided and feedback-based fuzz testing, to automatically generate millions of test cases that trigger hard-to-find bugs deep within your application. This white-box approach protects against edge cases and speeds up development. Advanced fuzzing engines generate inputs that maximize code coverage. Powerful bug detectors check for errors during code execution. Uncover true vulnerabilities only. Get the input and stack trace as proof, so you can reliably reproduce errors every time. AI white-box testing uses data from all previous test runs to continuously learn the inner-workings of your application, triggering security-critical bugs with increasingly high precision.

About

ToothPicker is an in-process, coverage-guided fuzzer for iOS. It was developed to specifically target iOS's Bluetooth daemon and to analyze various Bluetooth protocols on iOS. As it is built using FRIDA, it can be adapted to target any platform that runs FRIDA. This repository also includes an over-the-air fuzzer with an exemplary implementation to fuzz Apple's MagicPairing protocol using InternalBlue. Additionally, it contains the ReplayCrashFile script that can be used to verify crashes the in-process fuzzer has found. This is a very simple fuzzer that only flips bits and bytes of inactive connections. No coverage, no injection, but nice as a demo and stateful. Runs just with Python and Frida, no modules or installation are required. ToothPicker is built on the codebase of frizzer. It is recommended to set up a virtual Python environment for frizzer. Starting from the iPhone XR/Xs, PAC has been introduced.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Supported
Linux Not Supported
Cloud Not Supported
On-Premises Not Supported
iPhone Supported
iPad Supported
Android Not Supported
Chromebook Not Supported

Audience

Developers interested in an automated application security solution

Audience

Professional users interested in a fuzzing solution to test their iOS applications

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Pricing

Free
Free Version Supported
Free Trial Not Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Training

Documentation Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Company Information

Code Intelligence
Germany
www.code-intelligence.com

Company Information

Secure Mobile Networking Lab
github.com/seemoo-lab/toothpicker

Alternatives

go-fuzz

go-fuzz

dvyukov

Alternatives

LibFuzzer

LibFuzzer

LLVM Project
Mayhem

Mayhem

ForAllSecure
Atheris

Atheris

Google
LibFuzzer

LibFuzzer

LLVM Project
Jazzer

Jazzer

Code Intelligence
Atheris

Atheris

Google
syzkaller

syzkaller

Google
CI Fuzz

CI Fuzz

Code Intelligence
Honggfuzz

Honggfuzz

Google

Categories

Code Coverage Supported
Fuzz Testing Supported

Categories

Fuzz Testing Supported

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Not Supported
Source Code Analysis Not Supported
Third-Party Tools Integration Not Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Integrations

Apache Maven Supported
C Supported
C++ Supported
CLion Supported
CircleCI Supported
Docker Supported
GitHub Supported
GitLab Supported
Go Supported
Gradle Supported
JUnit Supported
Java Supported
JavaScript Supported
Jenkins Supported
Jira Supported
Kubernetes Supported
Python Not Supported
Vim Supported
Visual Basic Supported
Visual Studio Supported

Integrations

Apache Maven Not Supported
C Not Supported
C++ Not Supported
CLion Not Supported
CircleCI Not Supported
Docker Not Supported
GitHub Not Supported
GitLab Not Supported
Go Not Supported
Gradle Not Supported
JUnit Not Supported
Java Not Supported
JavaScript Not Supported
Jenkins Not Supported
Jira Not Supported
Kubernetes Not Supported
Python Supported
Vim Not Supported
Visual Basic Not Supported
Visual Studio Not Supported
Claim Code Intelligence and update features and information
Claim Code Intelligence and update features and information
Claim ToothPicker and update features and information
Claim ToothPicker and update features and information