Boofuzz Alternatives
Similar projects and alternatives to boofuzz
-
libfuzzer
Thin interface for libFuzzer, an in-process, coverage-guided, evolutionary fuzzing engine.
-
WorkOS
The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.
-
FDsploit
Discontinued File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
boofuzz reviews and mentions
-
Microsoft Teams, Exchange Server, Windows 10 Hacked in Pwn2Own 2021
The one thing that's not really fully encapsulated in a lot of these comment chains below is the role of custom written fuzzers for competitions like this. Frameworks like AFL, BooFuzz, etc. A properly written test file will allow for most of the hunting to happen automagically by tampering with function calls or inputs until something crashes. By configuring an environment appropriately, you can run millions of test cases, and get the crashes logged to parse through later. This allows the researchers/exploit writers to only focus on the exceptions/traces that seem the most fruitful. This is one methodology, it's not the case for everyone, but most codebases are too big to go through the ASM by hand these days.
Stats
jtpereyda/boofuzz is an open source project licensed under GNU General Public License v3.0 only which is an OSI approved license.
The primary programming language of boofuzz is Python.