pen-test
[Top] [All Lists]

Re: What protocol to choose for a new fuzzer?

To: pen-test@securityfocus.com
Subject: Re: What protocol to choose for a new fuzzer?
From: Nicolas RUFF <nicolas.ruff@gmail.com>
Date: Sun, 11 Mar 2007 10:15:09 +0100
Cc: Chris Byrd <cbyrd01@gmail.com>, "jezzzz ." <jezonthenet@yahoo.com>
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; b=IKvOiRLGV4C7VL2H7b4RhAaEYf1hPP9pv1jKWyam8bNH9Acb1THvXhP+mR2bJ45JZp5KuvrhHdGgWiD1FmUdM/fyAM0Qfm1kxWVlPlUL73/Ii5RUD9KhkqW2sFkRHkMCX+MiVrd0p3y5xhyLuKaWDKSg/dBSxboEHnQ0MXaaJyw=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; b=uUwq9Ix9e9r/Zk3A1YRf22eWlBB6/LLnRHK6QguS4WyI72KIIe+6k5YfeXyBsviVoCabcNmLuqyutFZVhPFK2ZXu0vRb84WVsyXWqbyOm/Opyym3kOepG49i41gvWekzx6CPNI7Bm5H0M1zwvBGWp5Z9UmBZDWGK3B45OYMRb0o=
In-reply-to: <6e7b3c5e0702210757p1e414fc4l104bf0a45158623a@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <81449.38836.qm@web58106.mail.re3.yahoo.com> <6e7b3c5e0702210757p1e414fc4l104bf0a45158623a@mail.gmail.com>
Resent-date: Tue, 13 Mar 2007 17:27:50 -0700 (MST)
Resent-from: pen-test-return-1078483750@securityfocus.com
Resent-message-id: <20070314002750.03BF923A0B0@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.10 (Windows/20070221)
> How about an IPv6 stack fuzzer?  Most IPv6 implementations are pretty
> new, and there's lots of potential for problems.   Its also on by
> default in new OSes.  Anyone on list know of any IPv6 fuzzers out
> there?

FYI, there is an IPv6-compliant port of Scapy :
http://namabiiru.hongo.wide.ad.jp/scapy6/

At the end, it gives :
http://www.cisco.com/warp/public/707/cisco-sa-20070124-IOS-IPv6.shtml


BTW, learning Python by writing a RDP/ICA fuzzer seems ... challenging,
to say the least !

Fuzzing LLDP sounds a good idea. Don't forget PNRP, PNM, LLTD, SMBv2 and
other Vista protocols ... And don't worry, we are working on them :)

Regards,
- Nicolas RUFF
Security Researcher @ EADS-IW

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>
  • Re: What protocol to choose for a new fuzzer?, Nicolas RUFF <=