Unveil the Depths of C/C++ Whitebox Fuzzing
Dive into specialized training, harnessing the power of whitebox fuzzing for robust C/C++ applications.
This course will teach you everything you need to know to start fuzzing C/C++ source code using different fuzzing techniques. You will learn how to use famous coverage-guided fuzzing framework (afl, libfuzzer, honggfuzz) and create custom fuzz target harnesses. Then, you will learn how to evaluate and improve your fuzzing results, debug and analyze crashes. Finally, you will discover some other more advanced testing techniques to find in-depth bugs. During the all training, you will target real-life/popular C/C++ libraries.
Along this training, students will deal with a lots of hands-on exercises allowing them to internalize concepts and techniques taught in class.
COURSE SYLLABUS
- Introduction to Fuzzing
- Coverage-guided Fuzzing
- afl / honggfuzz
- Improve your Fuzzing workflow
- Corpus/inputs selection
- Code coverage / Corpus minimization
- Crashes Analysis
- Crashes minimization / Bucketing / Debugging / Root cause analysis
- In-Memory fuzzing
- libfuzzer / afl / honggfuzz
- Generation-based fuzzing
- Structure-aware
- Grammar-based Fuzzing with dictionaries
- Other Advanced Testing techniques
- Symbolic Execution / Concolic Execution
- Differential Fuzzing
-
Prerequisites
-
Who should attend?
- Familiarity with Linux and C/C++.
- A working laptop capable of running virtual machines
- 4GB RAM required, at a minimum
- 40 GB free Hard disk space
- VirtualBox
- Administrator/root access MANDATORY
This course is suitable for people that are new to C/C++. All the theory and concepts about C/C++ fuzz testing will be explained during the course.
- Software developers
- Security engineers
- Vulnerability researchers
- Bug bounty hunters
- Pentesters & Red team professionals
- Anyone who want to learn more about C/C++ fuzzing
Testimonials
Any questions about our services and trainings ?
Get in touch today with any questions that you might have.