LibFuzzer

LibFuzzer

LLVM Project
+
+

Related Products

  • Parasoft
    139 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Wiz
    1,106 Ratings
    Visit Website
  • Boozang
    15 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • Orca Security
    495 Ratings
    Visit Website
  • SDS Manager
    4 Ratings
    Visit Website
  • QuantaStor
    6 Ratings
    Visit Website
  • JOpt.TourOptimizer
    10 Ratings
    Visit Website

About

LibFuzzer is an in-process, coverage-guided, evolutionary fuzzing engine. LibFuzzer is linked with the library under test, and feeds fuzzed inputs to the library via a specific fuzzing entry point (or target function); the fuzzer then tracks which areas of the code are reached, and generates mutations on the corpus of input data in order to maximize the code coverage. The code coverage information for libFuzzer is provided by LLVM’s SanitizerCoverage instrumentation. LibFuzzer is still fully supported in that important bugs will get fixed. The first step in using libFuzzer on a library is to implement a fuzz target, a function that accepts an array of bytes and does something interesting with these bytes using the API under test. Note that this fuzz target does not depend on libFuzzer in any way so it is possible and even desirable to use it with other fuzzing engines like AFL and/or Radamsa.

About

Fuzz testing or fuzzing is a software testing technique, that basically consists in finding implementation bugs using malformed/semi-malformed data injection in an automated fashion. Let’s consider an integer in a program, which stores the result of a user’s choice between 3 questions. When the user picks one, the choice will be 0, 1, or 2, which makes three practical cases. Integers are stored as a static size variable. If the default switch case hasn’t been implemented securely, the program may crash and lead to “classical” security issues. Fuzzing is the art of automatic bug finding, and its role is to find software implementation faults and identify them if possible. A fuzzer is a program that automatically injects semi-random data into a program/stack and detects bugs. The data-generation part is made of generators, and vulnerability identification relies on debugging tools. Generators usually use combinations of static fuzzing vectors.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Users requiring a fuzzing engine to analyze their code and applications

Audience

Professional users looking for a solution to find bugs automatically

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

LLVM Project
Founded: 2003
llvm.org/docs/LibFuzzer.html

Company Information

OWASP
United States
owasp.org/www-community/Fuzzing

Alternatives

afl-unicorn

afl-unicorn

Battelle

Alternatives

Atheris

Atheris

Google
ClusterFuzz

ClusterFuzz

Google
Jazzer

Jazzer

Code Intelligence
Honggfuzz

Honggfuzz

Google
LibFuzzer

LibFuzzer

LLVM Project

Categories

Categories

Integrations

Atheris
C
C++
CI Fuzz
ClusterFuzz
Fuzzbuzz
Google ClusterFuzz
Jazzer

Integrations

Atheris
C
C++
CI Fuzz
ClusterFuzz
Fuzzbuzz
Google ClusterFuzz
Jazzer
Claim LibFuzzer and update features and information
Claim LibFuzzer and update features and information
Claim OWASP WSFuzzer and update features and information
Claim OWASP WSFuzzer and update features and information