Skip to main content

dfuzz - automated daemon fuzzer

Project description

dfuzz - automatic daemon configuration fuzzer. Rather than being a fuzzer itself, dfuzz is a wrapper for other simple fuzzers solving few common flaws which makes automated testing a bit difficult.

Although its primary targets are configuration files, it is possible to use dfuzz to fuzz any input files.

The main problems dfuzz solves are:
  • alpha versions of fuzzers - most of the fuzzers are just alpha versions which are no longer developed or maintained

  • common format - no need to understand how to use every single underlying fuzzer

  • customizable monitoring and automatic error analysis

  • straightforward specification of what to test and which file to supply to the target

  • combination of mutation and generation of fuzzed files

Requirements

  • python >= 2.6

  • fuzzer (zzuf, autodafe, …)

  • gdb, valgrind (both are optional)

Features

  • independent of underlying fuzzer

  • highly configurable

  • built to be extendible

  • automation friendly

Supported fuzzers

  • zzuf (mutation)

  • autodafe (generation)

  • plain (debugging purposes)

Usage

  • install requirements

  • install dfuzz (for example easy_install dfuzz)

  • create a working directory

  • supply fuzz.conf file (sample follows)

  • according to the modules you want to use, create mut or gen directory in your working directory and supply a file to fuzz or a template to use

  • run dfuzz -d -o name_of_the_working_directory

  • observe output

  • if everything is fine remove the -d and -o options and run the command again

  • check the samples directory created in your working directory

  • use included incident_viewer to browser incidents if there are any

Complete documentation in docs directory.

Sample fuzz.conf file

[global]
binary=libvirtd
args=-f FUZZED_FILE --verbose
threads = 1
timeout = 2

generation  = 0
mutation    = 1
combination = 0

[generation]
modules  = dfuzz.gen.autodafe
priority = high

[mutation]
modules = dfuzz.mut.zzuf; dfuzz.mut.plain
priority = high

[combination]
modules = dfuzz.comb.simple
priority = low

In it’s simplest form, dfuzz can be used as a zzuf wrapper with enhanced detection and reporting capabilities.

Project details


Release history Release notifications | RSS feed

This version

0.6

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dfuzz-0.6.tar.gz (41.9 kB view details)

Uploaded Source

File details

Details for the file dfuzz-0.6.tar.gz.

File metadata

  • Download URL: dfuzz-0.6.tar.gz
  • Upload date:
  • Size: 41.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No

File hashes

Hashes for dfuzz-0.6.tar.gz
Algorithm Hash digest
SHA256 768c18e988d9c7c1472a576ea3ed68725968433648467acaafba2e478954e469
MD5 40df84cd9aff13a8ca1de6ceb8d23b47
BLAKE2b-256 d95916bf366fe6d075d0739ec83d493c57d1973375b41f545c0c942a78a36c0d

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page