~250 open source projects (https://github.com/google/oss-fuzz/tree/master/projects …) wrote their own fuzzers which are run on ClusterFuzz through OSS-Fuzz. That's probably more representative of the average dev outside Silicon Valley
-
-
- Još 2 druga odgovora
Novi razgovor -
-
-
Well, seems the next step is recycling unit or multi-unit tests (people write those, right?) to become fuzzing harnesses, no dev intervention. Seed with min/max values (quckcheck-like) or with just the unit tests oracles, or with symex. DeepState (
@trailofbits) FTW? -
The way to introduce fuzzing in an org is selling it as a dev tool, *not* a security tool. Once devs see it as a new tool that works for them, they start thinking on how to plug it everywhere. Use the cycles! Seehttps://twitter.com/cestlemieux/status/1176324852954714112?s=20 …
Kraj razgovora
Novi razgovor -
-
-
It does not matter, the future is coming with projects like https://fuzzbuzz.io/ or https://fuzzit.dev/ or (and this one is mind blowing if you think about possibilities)https://www.microsoft.com/en-us/security-risk-detection/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.