Recon 2022 - Training Announcement
Practical Web Browser Fuzzing Training
Kickstart your journey into the intricate world of web browser fuzzing at Recon 2022! This exclusive training, led by experts Patrick Ventuzelo, is your opportunity to master advanced fuzzing techniques and uncover vulnerabilities in some of the most widely used software globally.
Overview
Web browsers are among the most complex software systems, managing untrusted web data with millions of lines of code. Inevitably, bugs slip through the cracks, making security essential. This hands-on training will equip participants with the skills to apply fuzzing techniques for identifying critical vulnerabilities in leading web browser implementations like Chrome, Firefox, and WebKit.
The training begins with an introduction to modern web browser architecture, followed by practical sessions using tools like Honggfuzz, Domato, Fuzzilli, and AFL++. Participants will gain expertise in fuzzing browser components such as DOM, JavaScript engines, JIT compilers, WebAssembly, and IPC. Real-world use cases ensure a practical, impactful learning experience.
May 30- June 2, 2022
Recon (Montreal, Canada)
4 days
Intermediate
Patrick Ventuzelo
$4800
20 participants
Schedule
Day 1
- Morning: Browser Internals and Fuzzing Basics (Module 1)
- Afternoon: Fuzzing DOM & Rendering Engines (Module 2)
Day 2
- Morning: Fuzzing DOM & Rendering Engines (Module 2)
- Afternoon: Fuzzing JavaScript Engines & JIT Compilers (Module 3)
Day 3
- Morning: Fuzzing JavaScript Engines & JIT Compilers (Module 3)
- Afternoon: Fuzzing WebAssembly Compilers & APIs (Module 4)
Day 4
- Morning: Fuzzing WebAssembly Compilers & APIs (Module 4)
- Afternoon: Fuzzing IPC and Other Components (Module 5)
Your Instructors

Patrick Ventuzelo
Patrick Ventuzelo is a senior security researcher, CEO & founder of FuzzingLabs. After working for the French Ministry of Defense, he specialized in fuzzing, vulnerability research, and reverse engineering. Over the years, Patrick has created multiple fuzzers, found hundreds of bugs, and published various blog posts/videos/tools on topics like Rust, Go, Blockchain, WebAssembly, and Browser security. Patrick is a regular speaker and trainer at various security conferences around the globe, including BlackHat USA, OffensiveCon, REcon, RingZer0, PoC, ToorCon, hack.lu, NorthSec, SSTIC, and others.
Topics Covered
- Introduction to Fuzzing
- Modern Browser Architecture & major Components
- Setting up a Testing and Debugging environment
- Compile and Explore famous browser codebases
- Fuzzing Web Browsers Fundamentals
- Improving your Fuzzing Workflow & Automation
- Introduction to the Rendering engine
- HTML/CSS/XML Parsing
- Analysis of existing CVEs, Issues, and PoCs
- Blink, Gecko & WebKit Fuzzing
- DOM rendering & Implementation
- Fuzzing DOM using Grammar-based Fuzzing
- JavaScript Engine Internals & APIs
- Memory management and Garbage collection
- Analysis of existing CVEs, Issues, and PoCs
- V8, Spidermonkey & JavaScriptCore Fuzzing
- JIT compilers Internals
- TurboFan and IonMonkey Fuzzing
- Introduction to WebAssembly
- VM Architecture & Implementation
- Analysis of existing CVEs, Issues, and PoCs
- Fuzzing WebAssembly JavaScript APIs
- WebAssembly compilers internals
- WebAssembly In-process Fuzzing
- Inter-Process Communication (IPC) Internals
- Analysis of existing CVEs, Issues, and PoCs
- Fuzzing Chrome Mojo/Legacy IPC
- Discovery of other Components Implementation
- Networking/Data Persistence APIs
- Fuzzing Media and other Plugins
Prerequisites and requirements
- Familiarity with scripting (Python, Bash) and Linux.
- Familiarity with C/C++ and JavaScript.
- A working laptop capable of running virtual machines
- 8GB RAM required, at a minimum
- 80 GB free Hard disk space
- VirtualBox
- Administrator/root access MANDATORY
About Us
FuzzingLabs was founded in 2021 by Patrick Ventuzelo, a vulnerability researcher who spent more than ten years finding the flaws hidden in firmware and binaries. He built FuzzingLabs to turn that passion into a company, and to teach it.
Today, FuzzingLabs is a French team of researchers and engineers. They compete at Pwn2Own, present at Black Hat and OffensiveCon, and pour that same passion into FuzzForge, the platform at the heart of the company.
Any questions about our services and trainings ?
Let’s work together to ensure your peace of mind.
LATEST ARTICLES


