video thumbnail 14:41
How Fuzzing with AFL works!

2021-05-08

[public] 24.7K views, 2.00K likes, 10.0 dislikes audio only

channel thumbLiveOverflow

Let's investigate some issues we have fuzzing sudo with afl. And also explain how AFL works. After improving our fuzzing setup even more, we are finally read to start fuzzing sudo for real. Can we find the vulnerability now?

https://liveoverflow.com/support/

Grab the files: https://github.com/LiveOverflow/pwnedit/

milek7's blog: https://milek7.pl/howlongsudofuzz/

Sudo Research Episode 02:

00:00 - Recap

00:39 - Fixing AFL Crash Using LLVM mode

03:32 - Testing the AFL Instrumented Sudo Binary

04:11 - How Fuzzing with AFL works!

06:44 - Can AFL find the crash?

08:06 - Detour: busybox and argv[0]

09:48 - How could we discover "sudoedit"?

10:47 - Can AFL find "sudoedit" through magic?

11:25 - Include argv[0] in the testcases

13:06 - Parallel Fuzzing Setup

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Why Pick sudo as Research Target? | Ep. 01 by LiveOverflow
/youtube/video/uj1FTiczJSE
Recap
/youtube/video/COHUWuLTbdk?t=0
Fixing AFL Crash Using LLVM mode
/youtube/video/COHUWuLTbdk?t=39
Testing the AFL Instrumented Sudo Binary
/youtube/video/COHUWuLTbdk?t=212
How Fuzzing with AFL works!
/youtube/video/COHUWuLTbdk?t=251
Can AFL find the crash?
/youtube/video/COHUWuLTbdk?t=404
Detour: busybox and argv[0]
/youtube/video/COHUWuLTbdk?t=486
How could we discover "sudoedit"?
/youtube/video/COHUWuLTbdk?t=588
Can AFL find "sudoedit" through magic?
/youtube/video/COHUWuLTbdk?t=647
Include argv[0] in the testcases
/youtube/video/COHUWuLTbdk?t=685
Parallel Fuzzing Setup
/youtube/video/COHUWuLTbdk?t=786
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Sudo Vulnerability Walkthrough by LiveOverflow
/youtube/video/TLa2VqcGGEQ