Fuzzing: Brute Force Vulnerability Discovery

本书介绍了一种有效的软件安全测试方法——模糊测试。通过向软件输入随机数据来揭示潜在的安全漏洞。书中详细讲解了从测试设计到评估漏洞可利用性的全过程,并对比了变异型和生成型模糊器的特点。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

版权声明:原创作品,允许转载,转载时请务必以超链接形式标明文章原始出版、作者信息和本声明。否则将追究法律责任。 http://blog.youkuaiyun.com/topmvp - topmvp
Master One of Todays Most Powerful Techniques for Revealing Security Flaws!

Fuzzing has evolved into one of todays most effective approaches to test software security. To fuzz, you attach a programs inputs to a source of random data, and then systematically identify the failures that arise. Hackers have relied on fuzzing for years: Now, its your turn. In this book, renowned fuzzing experts show you how to use fuzzing to reveal weaknesses in your software before someone else does.

Fuzzing is the first and only book to cover fuzzing from start to finish, bringing disciplined best practices to a technique that has traditionally been implemented informally. The authors begin by reviewing how fuzzing works and outlining its crucial advantages over other security testing methods. Next, they introduce state-of-the-art fuzzing techniques for finding vulnerabilities in network protocols, file formats, and web applications; demonstrate the use of automated fuzzing tools; and present several insightful case histories showing fuzzing at work. Coverage includes:

*Why fuzzing simplifies test design and catches flaws other methods miss
*The fuzzing process: from identifying inputs to assessing exploitability
*Understanding the requirements for effective fuzzing
*Comparing mutation-based and generation-based fuzzers
*Using and automating environment variable and argument fuzzing
*Mastering in-memory fuzzing techniques
*Constructing custom fuzzing frameworks and tools
*Implementing intelligent fault detection

http://rapidshare.com/files/119698361/0321446119.rar
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值