pedram@smash:~/research$ cat fuzzing

# Fuzzing

Fuzzing is the art of throwing malformed input at software until something breaks, then working out why. I spent a good chunk of the mid 2000s at it: co-writing the book and building Sulley.

The book

Fuzzing: Brute Force Vulnerability Discovery
Michael Sutton, Adam Greene, Pedram Amini
Addison-Wesley, 2007 · ISBN 0-321-44611-9 · 513 pages

One of the first books on fuzzing, covering the methodology end to end, from local and remote targets through file formats, network protocols and web applications to building your own framework. Free to read, on me:

↓ download the pdf (55 MB)   or as a zip (45 MB)

Sulley

A pure-Python, fully automated and unattended fuzzing framework, released with Aaron Portnoy at Black Hat 2007. Sulley did more than generate data: it modeled protocols as graphs of blocks and primitives, watched the target through a debugger agent, restarted it after every crash, recorded the test case that killed it, and let you resume a session days later. Plenty of modern fuzzers still lean on those ideas.

Code: github.com/OpenRCE/sulley. It is unmaintained; for new work use boofuzz, the actively developed fork. See also code/sulley, and PaiMei, whose PyDbg debugger drives Sulley's process monitor.

pedram@smash:~$
type help or ls /bin, or press ⌘Ctrl+K to jump anywhere