netzob
boofuzz
Our great sponsors
netzob | boofuzz | |
---|---|---|
2 | 1 | |
747 | 1,957 | |
0.8% | - | |
0.0 | 7.3 | |
8 days ago | 3 days ago | |
Python | Python | |
GNU General Public License v3.0 only | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
netzob
- Netzob: Protocol Reverse Engineering, Modeling and Fuzzing
-
Awesome Penetration Testing
Netzob - Reverse engineering, traffic generation and fuzzing of communication protocols.
boofuzz
-
Microsoft Teams, Exchange Server, Windows 10 Hacked in Pwn2Own 2021
The one thing that's not really fully encapsulated in a lot of these comment chains below is the role of custom written fuzzers for competitions like this. Frameworks like AFL, BooFuzz, etc. A properly written test file will allow for most of the hunting to happen automagically by tampering with function calls or inputs until something crashes. By configuring an environment appropriately, you can run millions of test cases, and get the crashes logged to parse through later. This allows the researchers/exploit writers to only focus on the exceptions/traces that seem the most fruitful. This is one methodology, it's not the case for everyone, but most codebases are too big to go through the ASM by hand these days.
What are some alternatives?
scapy - Scapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3.
American Fuzzy Lop - american fuzzy lop - a security-oriented fuzzer
pyinstxtractor - PyInstaller Extractor
libfuzzer - Thin interface for libFuzzer, an in-process, coverage-guided, evolutionary fuzzing engine.
ktool - pip install k2l | Mach-O + Obj-C analysis TUI / CLI kit and library. Zero compiled deps, runs anywhere with a python interpreter.
CrossHair - An analysis tool for Python that blurs the line between testing and type systems.
fapro - Fake Protocol Server
dirsearch - Web path scanner
pwntools - CTF framework and exploit development library
FDsploit - File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
automata - A Python library for simulating finite automata, pushdown automata, and Turing machines
hypothesis - Hypothesis is a powerful, flexible, and easy to use library for property-based testing.