Archive for the ‘Fuzzing Book’ Category

Academic Use of the Fuzz-Book?

Monday, July 20th, 2009

I know it is being used in the academia… but it would be great to hear what you thought of it. Please submit anonymous comments here, or just email me if you have any feedback. Or just let us know that you have read the book!

First Review Added

Friday, April 24th, 2009

I know there have been several others, but for some reason I have forgotten to add them here. Please let us know if you have written or seen one somewhere.

One Of The Major Challenges In Writing A Fuzzing Book

Tuesday, March 17th, 2009

When you do work in fuzzing domain, it is extremely challenging sometimes to get people to speak about it. Most people see that using fuzzing gives such a competitive edge that revealing the use of fuzzing tools would hurt them in the process. Things really changed during last year. We now have people reporting huge ROI using fuzzing (and publicly). We have leading Fortune-500 companies dictating the use of fuzzing in their RFPs in the procurement process. We also see marketing campaigns from companies like Google publicly advertising how proud they are that they also do fuzzing.

The BSIMM study by Cigital creates a new mile stone in the domain of market studies in fuzzing. It might not even attempt to describe how common the use of fuzzing is. The sample of companies also do not really indicate anything about the rest of the users of fuzzers. And the interview process itself might have not really given much emphasis on fuzzing, as all the authors really come from the static analysis mindset. But surprisingly enough, all top product security teams were found to be doing fuzzing already!

Another major milestone is studying the use of fuzzing is the inclusion of fuzzing related questions to the Forrester questionnaire, completed by thousands of CIO/CSO/CISO people annually.

I personally look forward to hearing what Cigital and Forrester have to say about the use of fuzzing. If you are interested, please give us a shout here: Fuzzing 101

Reminder: Absolutely Finally The Last Chance To Win

Wednesday, January 21st, 2009

… until we get a new sponsor for some more books to give out! Tell us why you should have one of the books, and surprise surprise you might get one!

http://www.codenomicon.com/fuzzing-book/

Winners Have Been Notified

Monday, October 6th, 2008

Eight lucky winners have been notified. The publisher should send more copies shortly (only received six so far) and then the fuzzing process will continue… Until then, we are still accepting new participants to the draw!

The best “Why Me” comments are also under selection process. Here is a sample of some of them (from current winners, who unfortunately will not get a chance to get a second copy):

  • “I’ve got to have it! They’re all out to get me!” by Steve Abler
  • “I am passionate about application security and the need for robust testing methods. I am an application security evangelist who proactively educates developers, development mangers, security practitioners and executive management. I am currently lobbying for a corporate team to be tasked with supporting SSDLC using whitebox and blackbox tools. In short, I am someone who will both benefit from and provide value with the knowledge I can gain from this book.” by Jaime Castells
  • “Because it is the first resource I’ve seen that connects the dots between software QA and IT security - two topics that have fascinated, frustrated, and perplexed me for many years.” by Alex Chapman
  • “Keep your friends close and your enemies closer. Having this book will help me to keep hackers close but not that close.” by Richard N Price
  • “I need to understand the threats facing our applications better. We want to pull together a lab where we don’t just interrogate software (checking what APIs are called and if the app has the authorization) we want to black box test the app. The book would help us realize that goal.” by Loraine Beyer
  • “To restore my faith in Lady Luck.” by Laszlo Bortel
  • “Application testing for security flaws has become the next major defense against blended threats and this book shows you how to start and improve your fuzzing skills.” by Russell Weatherly
  • “SW Quality is a fuzzy subject, SW Security Quality doubly so! As a quality expert I see security testing important, but find that engineering the SW security quality intentionally in place in the development process is even more critical. I (and my team) needs to learn this.” by Erkki Pöyhönen

Congratulations to all winners!

Book Draw Results Oct 05

Thursday, October 2nd, 2008

Last chance to participate in the book draw … I will (try to) email everyone with the result, whether you won or not. So no worries if you have not heard from me yet!

Update: My ITworld blog

Win A Free Copy Of The Book!

Tuesday, September 9th, 2008

We received ten copies to give out to those who are interested. More details here: http://www.codenomicon.com/fuzzing-book/

First Review On Amazon!

Monday, September 8th, 2008

Please submit more reviews for the book! Positive ones I hope! That way we can have the opportunity to update the book also in the future.

In the review Robert commented: “At least two of the authors have worked at the National Security Agency.” - No, I have not worked for NSA (as far as I know). Jared and Charlie have, as all of you know already.

Yes, The Book Is Really Out

Monday, September 8th, 2008

I received my copies a while ago (feels like ages ago, but it really was just weeks ago). I am sure you all appreciate the fact that paying customers received copies before authors. ;)

Anyways, we received ten extra copies to give out to our “fans”. I will post details of the draw later this week. Send me email if you think that you should definitely be sent a copy. Best reasoning why you should receive one will get a personally signed copy from me.

I still feel a bit allergic to the book, having spent so much time with it. It is difficult to open it up and read it, so I appreciate if you send information about errors either by email or through comments in this wiki. We will most probably start collecting an errata here, so that you can review if we are already aware of the bugs you find.

The Book is Finally Out?

Tuesday, July 8th, 2008

It is a small step for human kind, but a huge leap for our book project. After years and years of sweat and tears, the fuzzing book by me, Jared and Charlie should now be in the warehouses being shipped to bookstores. I still personally have not seen a copy, but apparently it is now finally out.

Please let us know what you think of the book when you get your copy!