Stream: wg-secure-code

Topic: Angora


Shnatsel (Dec 28 2018 at 19:40, on Zulip):

Source code for a new fuzzer that, according to its developers, vastly outperforms everything existing to date has just been released: https://github.com/AngoraFuzzer/Angora
It is written at least partially in Rust. Uses LLVM 4.0 so probably can't instrument Rust code just yet.

Shnatsel (Dec 28 2018 at 19:41, on Zulip):

If you want to claim some CVEs and bug bounties to your name, this is your chance. I did it back when AFL dropped, and I'm kind of bored of that already.

Alex Gaynor (Dec 29 2018 at 00:41, on Zulip):

I found the claims about how effective it is very difficult to follow -- specifically I couldn't tell if all the findings were against LAVA injected vulnerabilities, or if it found things in real programs.

Shnatsel (Dec 29 2018 at 11:43, on Zulip):

both

Last update: Nov 11 2019 at 23:15UTC