Главная
Study mode:
on
1
Intro
2
Overview
3
Quick Recap
4
Splicing
5
Converting to JavaScript
6
Finding bugs
7
What is code coverage
8
Where are the bugs
9
A classic bug
10
probingmutator
11
Bug example
12
Expiration example
13
Cold coverage feedback
14
Complexity analysis
15
Wildback
16
Example
17
Program Templates
18
Hybrid Engine
19
Regular Expression Engine
20
Mini Fuzzers
21
Destroyalization
22
Program Space
23
Summary
Description:
Explore advancements in JavaScript engine fuzzing through this conference talk by Samuel Groß and Carl Smith at OffensiveCon23. Delve into topics such as splicing, converting to JavaScript, and finding bugs through code coverage analysis. Learn about probing, mutator techniques, and examine real-world bug examples, including expiration issues. Discover cold coverage feedback methods and complexity analysis tools like Wildback. Gain insights into program templates, hybrid engines, and regular expression engines. Investigate mini fuzzers, destructialization techniques, and program space concepts. This 23-minute presentation offers a comprehensive overview of cutting-edge JavaScript engine fuzzing techniques for security researchers and developers.

Advancements in JavaScript Engine Fuzzing - OffensiveCon 2023

OffensiveCon
Add to list
0:00 / 0:00