[Dailydave] [fuzzing] Coverage and a recent paper by L. Suto

Nicolas RUFF nruff at security-labs.org
Sat Oct 27 03:25:47 EDT 2007


> Using the following perl script two buffer overflows are detected:
> cat vuln.c | perl -ne '/rnd\[i\]/ and print "Buffer overflow!\n"'
> This post does have a point. Discuss among yourselves.

Is this vendor bashing, maybe ? ;)

BTW, since you wrote your own static analyzer [*], I guess you could
share insights on the matter.

[*] http://gcc.vulncheck.org/

Regards,
- Nicolas RUFF


More information about the Dailydave mailing list