Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An instrumented fuzzer like AFL purports to do this:

http://lcamtuf.coredump.cx/afl/

This blog post is a fascinating description of its potential:

http://lcamtuf.blogspot.com/2014/11/pulling-jpegs-out-of-thi...

I haven't had as much success with it, but it's so interesting that I'll keep trying. I'm also interested in KLEE, which I found in a similar HN story, but it has very specific build requirements:

https://klee.github.io

[Edit: bhouston posted the exact same links minutes before I did. Anyway, cool stuff.]



KLEE is pretty cool. To compensate for the atrocious build instructions there's a docker image which contains KLEE built and ready to use (https://registry.hub.docker.com/u/kleeweb/klee/).

There's also a web interface to just play around with KLEE without having to download and install anything that a few other people and I worked on available at http://klee.doc.ic.ac.uk:55080/, which we open-sourced https://github.com/klee-web/klee-web.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: