addisoncrump.info/research/wha...
addisoncrump.info/research/wha...
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()
Please follow our workshop account @sureworkshop and RT it for visibility :).
Please follow our workshop account @sureworkshop and RT it for visibility :).
📝https://mpi-softsec.github.io/papers/ISSTA25-topscore.pdf
🧑💻https://github.com/niklasrisse/TopScoreWrongExam
// @nrisse.bsky.social @fuzzing.bsky.social
📝https://mpi-softsec.github.io/papers/ISSTA25-topscore.pdf
🧑💻https://github.com/niklasrisse/TopScoreWrongExam
// @nrisse.bsky.social @fuzzing.bsky.social
Vote whatever Elon didn't endorse
Vote whatever Elon didn't endorse
Go check it out at https://github.com/googleprojectzero/fuzzilli.
While we still have a way to go in improving it, we think it shows a promising approach!
Go check it out at https://github.com/googleprojectzero/fuzzilli.
While we still have a way to go in improving it, we think it shows a promising approach!
PDFs support Javascript, so Emscripten is used to compile the TinyEMU emulator to asm.js, which runs in the PDF. It boots in about 30 seconds and emulates a riscv32 buildroot system.
linux.doompdf.dev/linux.pdf
github.com/ading2210/li...
PDFs support Javascript, so Emscripten is used to compile the TinyEMU emulator to asm.js, which runs in the PDF. It boots in about 30 seconds and emulates a riscv32 buildroot system.
linux.doompdf.dev/linux.pdf
github.com/ading2210/li...
📝 mboehme.github.io/paper/ICSE25...
🧑💻 github.com/OctavioGalla... (subject to AE)
//Lead by Octavio Galland (former #MPI_SP intern).
📝 mboehme.github.io/paper/ICSE25...
🧑💻 github.com/OctavioGalla... (subject to AE)
//Lead by Octavio Galland (former #MPI_SP intern).
Really like this paper. Instead of writing a libfuzzer harness, use the state&arguments from test/E2E fuzzing and note what args can be fuzzed. Interesting follow ups: How to validate a crash in E2E setting & inferring amplification points & constraints dynamically.
Really like this paper. Instead of writing a libfuzzer harness, use the state&arguments from test/E2E fuzzing and note what args can be fuzzed. Interesting follow ups: How to validate a crash in E2E setting & inferring amplification points & constraints dynamically.
go.bsky.app/EhGFSVj
go.bsky.app/EhGFSVj
Me: ...
Company: *holds up diagram of 8 services, 15 databases, and a home grown queue implementation*
Me: You fucked up a perfectly good distributed system is what you did. Look at that thing, it's got clock skew.
Me: ...
Company: *holds up diagram of 8 services, 15 databases, and a home grown queue implementation*
Me: You fucked up a perfectly good distributed system is what you did. Look at that thing, it's got clock skew.