pen-test
[Top] [All Lists]

RE: What protocol to choose for a new fuzzer?

To: "'jezzzz .'" <jezonthenet@yahoo.com>, <pen-test@securityfocus.com>
Subject: RE: What protocol to choose for a new fuzzer?
From: "Paul Melson" <pmelson@gmail.com>
Date: Wed, 21 Feb 2007 14:41:13 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:to:references:subject:date:message-id:mime-version:content-type:content-transfer-encoding:x-mailer:x-mimeole:in-reply-to:thread-index; b=n2lDEIVwQqyBCgIi9/nKeyLmokBK5kvgtq+jw7PhggyLLzKQrNwvKzYUGjf5EvU/TB52J63zKoJAEaTkeS4d4XHnTvQlqPtpT1JB2BW1R/tK1VEDY9yYDSSVFBOQH4vp8tuAnqhmLot6EIGiQ0FrxoxEI++qZlNxMm/O1QpfuXg=
In-reply-to: <81449.38836.qm@web58106.mail.re3.yahoo.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <81449.38836.qm@web58106.mail.re3.yahoo.com>
Resent-date: Wed, 21 Feb 2007 21:20:15 -0700 (MST)
Resent-from: pen-test-return-1078483598@securityfocus.com
Resent-message-id: <20070222042015.016C4144D52@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: AcdVToYpK97CvgHmQdGdHheUZnU7NQAoZI+A
> I have some time on my hands (about two months) to work on a new network
protocol fuzzer which I intend 
> to write in Python. I don't have much experience in Python but my
intention is to learn it by writing 
> the fuzzer. I am looking for a protocol which is interesting and does not
yet have a fuzzer for it.
> IMAP and RIP for instance already seem to have fuzzers. Anyone any ideas
for other protocols?

What about Microsoft Remote Desktop (RDP) or Citrix ICA?  These protocols
are commonly found in pen tests, but there's a lack of tools for testing
against them.

PaulM



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>