Andrey Fedotov
@anfedotoff
Followers
52
Following
545
Media
7
Statuses
101
Computer scientist, Ph.D.
Москва, Россия
Joined December 2020
CASR is open-sourced: https://t.co/32nMnNd60I Triage crashes, estimate their severity, and collect reports cargo install casr #rust #fuzzing
github.com
Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity. - ispras/casr
0
7
20
🐝New Cilium Contributor🐝 The newest Cilium contributor is @anfedotoff They helped add support for user mode stack traces in events. https://t.co/ACIFlXGQPS
github.com
Hi 👋! I was inspired by #1429 and decided to add the ability for collecting user mode stacktraces. User-mode stacktraces allow you to enrich information about events and understand why this event...
0
1
7
The blog post about the libwebp vulnerability fuzzing is up, it explains how I set up the experiment, how the crash was found and why oss-fuzz was not able to find it: https://t.co/wuwK2Vj6VO
#fuzzing @metzmanj
srlabs.de
The question the fuzzing community and we were asking – is it possible to find this specific vulnerability with fuzzing? And if so, why was it not found in Google‘s OSS-Fuzz initiative? This article...
3
73
233
As there is quite some interest about finding the libwebp bug with fuzzing, I will write a blog entry about this next week #fuzzing
1
7
58
My talk about #casr at OFFZONE 2023!!! Slides: https://t.co/iXChrPv0pq Video (in Russian): https://t.co/A3wJ6m3eFL
#fuzzing
0
1
6
Simply deduplicate and create reports for #UndefinedBehaviorSanitizer warnings with Casr: casr-ubsan -i corpus -o out -- /fuzz_target @@ https://t.co/5OA6MaBpnT
#casr #defectdojo #vulnerabilitymanagement #VulnerabilityAssesment #AppSec #DevSecOps
0
2
9
Almost a year after my defense, my PhD thesis "Automated Security Testing of Unexplored Targets Through Feedback-Guided Fuzzing" is now archived on the university server 🎉 We fuzzed Nvidia drivers, tcp servers, basebands, WebAssembly, .. Enjoy reading :) https://t.co/aBHy2X74iP
14
134
551
casr-dojo: upload new and unique #crash reports found by #fuzzing to @defectdojo vulnerability management system: https://t.co/aa1RDRIOzx
#casr #defectdojo #vulnerabilitymanagement #VulnerabilityAssesment #AppSec #DevSecOps #cpp #rust #go #python
0
3
10
https://t.co/uPqN39esnI
#casr 2.6.0, what's new: casr-libfuzzer tool for triaging crashes found by libFuzzer based fuzzers (C/C++/go-fuzz/Atheris) kodama crate for clustering instead of python scipy RISCV support #fuzzing
github.com
casr-libfuzzer tool for triaging crashes found by libFuzzer based fuzzers (C/C++/go-fuzz/Atheris) kodama crate for clustering instead of python scipy riscv support clap 4.2 for options parsing
0
2
6
Spice up your binary program analysis with TritonDSE ! A blog post by Christian Heitman and @RobinDavid1 introducing our framework for Dynamic Symbolic Execution in Python #symexec #fuzzing #opensource
https://t.co/fay9SlKee7
0
22
56
I wish tutorial articles would all have a date when they got published and last updated. Followed a tutorial which was not working, spent time trying to fix it and then found out the API has been changed in 2017
3
1
9
As it turns out, compilers happily spill the index for indirect jumps through a jump table after bounds checking, creating a TOCTTOU race for arbitrary control-flow hijacking. Check out our @HexHiveEPFL @IEEESSP "WarpAttack" paper: https://t.co/hBYmGqeh0N
2
48
197
casr-libfuzzer: triage crashes in C/C++/Go/Python code found by libFuzzer/Atheris/go-fuzz casr-libfuzzer -o out -- /fuzz_target https://t.co/WK4Ewx597O
#casr #fuzzing #libfuzzer #atheris #go #python #cpp
1
7
47
https://t.co/T0DROqYK9Z
#casr 2.5.0, what's new: #libcasr: library for crash triage, stacktrace parsing, severity estimation, and collecting crash reports. Crash triaging for Go panics AARCH64 support #fuzzing
github.com
libCASR: a library for triaging and severity estimation of crashes crash triaging for Go panics crash triaging for AARCH64 binaries improved stacktrace filtering added environment variables to casr...
0
1
3
Excited to present new(?) approach to #fuzzing where one doesn't need to write fuzz functions. Wanna fuzz all binaries on github - no problem. Just give the fuzzer binaries to test. No false positives & 100% fidelity. Blender: whole-program fuzzing: https://t.co/K0ZQw2L1As
7
66
217
Very nice collection of publications about #fuzzing:
google.github.io
Documentation for FuzzBench
0
0
0
My blog post about #fuzzing #go project golang/image: https://t.co/36RtuAMlBR 0. Changing existing fuzz target to find new bugs. 1. Approach for code coverage collection after fuzzing with go-fuzz libFuzzer. 2. Go panic triage with #casr. 3. Fix:
github.com
OSS-Sydr-Fuzz - OSS-Fuzz fork for hybrid fuzzing (fuzzer+DSE) open source software. - ispras/oss-sydr-fuzz
0
4
5
Auto-fuzz: we recently pushed a tool for auto generation of Python #fuzzers and #OSS-Fuzz integrations. Early days, but it can create some valid integrations and many pieces will come together in the near future -- follow along :)! https://t.co/jWbT3ywzUf
1
21
70
Not the first time I'm convinced that using more the one fuzzer/symbolic executor it's a good idea. Just used @aflplusplus on known image-rs targets and found some issues: https://t.co/9qxvgHWVfp
https://t.co/EiLcpm6jSA
#fuzzing
github.com
Hi! I've been fuzzing image-rs crate with AFL++ using this fuzz target and found a capacity overflow. I think it is better not to panic if we couldn't allocate memory. So, I tried t...
0
0
1
We just released Fuzzilli v0.9.3: https://t.co/3kbRSBpBsq ... and more cool stuff is coming soon :) Happy Fuzzing!
github.com
Besides various bug fixes and stability/performance improvements, notable new features of this release include: The new ProbingMutator An improved lifting algorithm that can inline expression and ...
0
34
155