Embracing an Adversarial Mindset for Cpp Securityvetted parsers (JSON, XML, etc) ● Call to Action: Owners of OSS should onboard to a fuzzing service (OSS-Fuzz)Isolation ● Untrusted Process – Parsing Out-of-Process ● Sandboxing ● AppContainers – Consider What the Fuzz) ● Structure Aware Fuzzing (libprotobuf-mutator) ● Fuzzing as a Service (OneFuzz, OSS-Fuzz)Libfuzzer and ASan The bar is not high, write simple function: FUZZ_EXPORT int __cdecl LLVMFu https://github.com/google/libprotobuf-mutator https://github.com/microsoft/onefuzz https://github.com/google/oss-fuzz© Copyright Microsoft Corporation. All rights reserved.0 码力 | 92 页 | 3.67 MB | 6 月前3
共 1 条
- 1













