Главная
Study mode:
on
1
Intro
2
Traditional Fuzzing
3
Types of Bugs: Crashes (cont).
4
Different Implementations
5
Different Inputs
6
Different Versions
7
Different OS (cont).
8
Extended Differential Fuzzing Framework
9
Extended Differential Fuzzing: Python 1/3
10
Extended Differential Fuzzing: Perl
11
Extended Differential Fuzzing: JavaScript
12
Extended Differential Fuzzing: JRuby
13
Extended Differential Fuzzing: PHP 1/4
14
Extended Differential Fuzzing: PHP 4/4
15
Black Hat Sound Bytes
Description:
Explore a conference talk that uncovers critical vulnerabilities in programming languages through differential fuzzing techniques. Learn about undocumented functions enabling OS command execution, exposure of sensitive file contents in error messages, unexpected interpretation of native code, and potential misuse of constant names as strings for OS commands. Discover practical examples and findings across Python, Perl, JavaScript, JRuby, and PHP implementations. Gain insights into the extended differential fuzzing framework and its application to various programming languages, revealing hidden exploitable behaviors that could compromise system security.

Exposing Hidden Exploitable Behaviors in Programming Languages Using Differential Fuzzing

Black Hat
Add to list
0:00 / 0:00