ToothPicker

ToothPicker

Secure Mobile Networking Lab
beSTORM

beSTORM

Beyond Security (Fortra)
+
+

Related Products

  • VKS
    26 Ratings
    Visit Website
  • LM-Kit.NET
    29 Ratings
    Visit Website
  • GoCodes
    274 Ratings
    Visit Website
  • Ditto
    2 Ratings
    Visit Website
  • QuantaStor
    6 Ratings
    Visit Website
  • QA Wolf
    269 Ratings
    Visit Website
  • AuthorityTech
    2 Ratings
    Visit Website
  • Orca Security
    594 Ratings
    Visit Website
  • Parasoft
    148 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website

About

ToothPicker is an in-process, coverage-guided fuzzer for iOS. It was developed to specifically target iOS's Bluetooth daemon and to analyze various Bluetooth protocols on iOS. As it is built using FRIDA, it can be adapted to target any platform that runs FRIDA. This repository also includes an over-the-air fuzzer with an exemplary implementation to fuzz Apple's MagicPairing protocol using InternalBlue. Additionally, it contains the ReplayCrashFile script that can be used to verify crashes the in-process fuzzer has found. This is a very simple fuzzer that only flips bits and bytes of inactive connections. No coverage, no injection, but nice as a demo and stateful. Runs just with Python and Frida, no modules or installation are required. ToothPicker is built on the codebase of frizzer. It is recommended to set up a virtual Python environment for frizzer. Starting from the iPhone XR/Xs, PAC has been introduced.

About

Discover code weaknesses and certify the security strength of any product without access to source code. Test any protocol or hardware with beSTORM, even those used in IoT, process control, CANbus compatible automotive and aerospace. Realtime fuzzing, doesn’t need access to the source code, no cases to download. One platform, one GUI to learn, with over 250+ prebuilt protocol testing modules and the ability to add custom and proprietary ones. Find the security weaknesses before deployment that are most often discovered by external actors after release. Certify vendor components and your own applications in your own testing center. Self-learning software module and propriety software testing. Customization and scalability for any business sizes up or down. Automatically generate and deliver near-infinite attack vectors and document any product failures. Record every pass/fail and hand engineering the exact command that produced each fail.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Professional users interested in a fuzzing solution to test their iOS applications

Audience

Cybersecurity staff requiring a tool to perform comprehensive, dynamic black box security testing

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

$50,000.00/one-time
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

Secure Mobile Networking Lab
github.com/seemoo-lab/toothpicker

Company Information

Beyond Security (Fortra)
Founded: 1999
United States
beyondsecurity.com/solutions/bestorm-dynamic-application-security-testing.html

Alternatives

LibFuzzer

LibFuzzer

LLVM Project

Alternatives

Atheris

Atheris

Google
Mayhem

Mayhem

ForAllSecure
Jazzer

Jazzer

Code Intelligence
NeoLoad

NeoLoad

Tricentis
syzkaller

syzkaller

Google
Honggfuzz

Honggfuzz

Google
go-fuzz

go-fuzz

dvyukov

Categories

Categories

Automated Testing Features

Hierarchical View
Move & Copy
Parameterized Testing
Requirements-Based Testing
Security Testing
Supports Parallel Execution
Test Script Reviews
Unicode Compliance

Integrations

Python

Integrations

Python
Claim ToothPicker and update features and information
Claim ToothPicker and update features and information
Claim beSTORM and update features and information
Claim beSTORM and update features and information