[Dailydave] From blackbox to grey-box during Web App tests

Andre Gironda andre at operations.net
Thu Oct 11 13:48:22 EDT 2007


On 10/10/07, Thomas Ptacek <tqbf at matasano.com> wrote:
> It's nice that they're doing this for JVM, but isn't this exactly what
> PaiMei and BinNavi (and, if you want to get snarky, gcov) do for
> native binaries?

PaiMei and BinNavi are fuzzer trackers, as I explained.  gcov is more
of a basic line coverage tool, isn't it?  See:
http://bullseye.com/coverage.html

> Can someone help me understand what web app magic this tool adds?

Here is the presentation where I first learned about what Tracer
actually does, inferring why it was created and what its uses are -
http://www.blackhat.com/presentations/bh-europe-07/Kureha/Presentation/bh-eu-07-chess-kureha-ppt-apr19.pdf

Cheers,
Andre


More information about the Dailydave mailing list