+
+

Related Products

  • c/side
    23 Ratings
    Visit Website
  • ManageEngine ADManager Plus
    578 Ratings
    Visit Website
  • A10 Defend Threat Control
    32 Ratings
    Visit Website
  • Chainguard
    43 Ratings
    Visit Website
  • Cerberus FTP Server
    159 Ratings
    Visit Website
  • EasyDMARC
    168 Ratings
    Visit Website
  • ManageEngine OpManager
    1,526 Ratings
    Visit Website
  • NINJIO
    393 Ratings
    Visit Website
  • Boozang
    15 Ratings
    Visit Website
  • QuantaStor
    6 Ratings
    Visit Website

About

FuzzDB was created to increase the likelihood of finding application security vulnerabilities through dynamic application security testing. It's the first and most comprehensive open dictionary of fault injection patterns, predictable resource locations, and regex for matching server responses. FuzzDB contains comprehensive lists of attack payload primitives for fault injection testing. These patterns, categorized by the attack and where appropriate platform type, are known to cause issues like OS command injection, directory listings, directory traversals, source exposure, file upload bypass, authentication bypass, XSS, HTTP header crlf injections, SQL injection, NoSQL injection, and more. For example, FuzzDB catalogs 56 patterns that can potentially be interpreted as a null byte and contains lists of commonly used methods and name-value pairs that trigger debug modes.

About

Fuzz testing or fuzzing is a software testing technique, that basically consists in finding implementation bugs using malformed/semi-malformed data injection in an automated fashion. Let’s consider an integer in a program, which stores the result of a user’s choice between 3 questions. When the user picks one, the choice will be 0, 1, or 2, which makes three practical cases. Integers are stored as a static size variable. If the default switch case hasn’t been implemented securely, the program may crash and lead to “classical” security issues. Fuzzing is the art of automatic bug finding, and its role is to find software implementation faults and identify them if possible. A fuzzer is a program that automatically injects semi-random data into a program/stack and detects bugs. The data-generation part is made of generators, and vulnerability identification relies on debugging tools. Generators usually use combinations of static fuzzing vectors.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Anyone requiring a security scanner solution to test their application protocols

Audience

Professional users looking for a solution to find bugs automatically

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

FuzzDB
github.com/fuzzdb-project/fuzzdb

Company Information

OWASP
United States
owasp.org/www-community/Fuzzing

Alternatives

Alternatives

API Fuzzer

API Fuzzer

Fuzzapi
ClusterFuzz

ClusterFuzz

Google
CI Fuzz

CI Fuzz

Code Intelligence
LibFuzzer

LibFuzzer

LLVM Project

Categories

Categories

Integrations

BlackArch Linux
CI Fuzz
NoSQL
OWASP ZAP

Integrations

BlackArch Linux
CI Fuzz
NoSQL
OWASP ZAP
Claim FuzzDB and update features and information
Claim FuzzDB and update features and information
Claim OWASP WSFuzzer and update features and information
Claim OWASP WSFuzzer and update features and information