<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fuzzing for Software Security Testing and Quality Assurance</title>
	<atom:link href="http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/feed/" rel="self" type="application/rss+xml" />
	<link>http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/</link>
	<description>Resources for Quality Assurance</description>
	<lastBuildDate>Tue, 17 Aug 2010 00:23:24 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: User 1138</title>
		<link>http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/comment-page-1/#comment-364</link>
		<dc:creator>User 1138</dc:creator>
		<pubDate>Thu, 11 Feb 2010 16:18:13 +0000</pubDate>
		<guid isPermaLink="false">http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/#comment-364</guid>
		<description>The introduction to this book mentions its broken up history, being picked up and abandoned a couple times. It definitely shows in the writing, which is unfocused, choppy, and repetitive. Most of the first half is taken up with repetitive descriptions of the general software testing process. The second half contains a summary of one author&#039;s thesis on using evolutionary algorithms for fuzzing and the final author&#039;s use of various fuzzing tools to try to find hand-inserted vulnerabilities. While the latter half is better than the first, each topic is worthy of a single blog post. Given this book&#039;s price and the authors&#039; reputations, I expected more.
&lt;br /&gt;
&lt;br /&gt;At the same time, I read &quot;Gray Hat Python&quot; and it was enjoyable. Even though it had a much broader focus on other topics, it contained more hands-on info on fuzzing tools. I&#039;m also interested in &quot;Fuzzing: Brute Force Vulnerability Discovery&quot;, although I have not read it yet.
&lt;br /&gt;
&lt;br /&gt;Don&#039;t waste your time on this book. Download the Sulley manual, read the slides from a few Blackhat talks, and you&#039;ll be at the state of the art for current fuzzing knowledge.
Rating: 1 / 5</description>
		<content:encoded><![CDATA[<p>The introduction to this book mentions its broken up history, being picked up and abandoned a couple times. It definitely shows in the writing, which is unfocused, choppy, and repetitive. Most of the first half is taken up with repetitive descriptions of the general software testing process. The second half contains a summary of one author&#8217;s thesis on using evolutionary algorithms for fuzzing and the final author&#8217;s use of various fuzzing tools to try to find hand-inserted vulnerabilities. While the latter half is better than the first, each topic is worthy of a single blog post. Given this book&#8217;s price and the authors&#8217; reputations, I expected more.</p>
<p>At the same time, I read &#8220;Gray Hat Python&#8221; and it was enjoyable. Even though it had a much broader focus on other topics, it contained more hands-on info on fuzzing tools. I&#8217;m also interested in &#8220;Fuzzing: Brute Force Vulnerability Discovery&#8221;, although I have not read it yet.</p>
<p>Don&#8217;t waste your time on this book. Download the Sulley manual, read the slides from a few Blackhat talks, and you&#8217;ll be at the state of the art for current fuzzing knowledge.<br />
Rating: 1 / 5</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Hudock</title>
		<link>http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/comment-page-1/#comment-363</link>
		<dc:creator>Robert Hudock</dc:creator>
		<pubDate>Thu, 11 Feb 2010 15:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://qalibrary.com/testing/sectest/fuzzing-for-software-security-testing-and-quality-assurance/#comment-363</guid>
		<description>Fuzzing generally involves testing the parameters of an application using random or specifically formatted randomized input to evaluate whether a given application crashes and/ or can be exploited.  At least two of the authors have worked at the National Security Agency.   Dr. Charlie Miller is well known for publishing an interesting article on the economics of the black market trading of security vulnerabilities (avaliable at weis2007.econinfosec.org/papers/29.pdf).  Dr. Miller demonstrated the utility of the procedures discussed in this book at BlackHat 2008.  This book provides insight into an area of research that is not usually publicly avaliable.  The book details a number of open-source and commercially avaliable fuzzers and their relative reliability in finding bugs.  Fuzzers are one of the most reliable methods for finding vulnerabilities in closed source programs.  The book is conceptually accessible to an individual with some knowledge of secure programming and vulnerabilities.
Rating: 5 / 5</description>
		<content:encoded><![CDATA[<p>Fuzzing generally involves testing the parameters of an application using random or specifically formatted randomized input to evaluate whether a given application crashes and/ or can be exploited.  At least two of the authors have worked at the National Security Agency.   Dr. Charlie Miller is well known for publishing an interesting article on the economics of the black market trading of security vulnerabilities (avaliable at weis2007.econinfosec.org/papers/29.pdf).  Dr. Miller demonstrated the utility of the procedures discussed in this book at BlackHat 2008.  This book provides insight into an area of research that is not usually publicly avaliable.  The book details a number of open-source and commercially avaliable fuzzers and their relative reliability in finding bugs.  Fuzzers are one of the most reliable methods for finding vulnerabilities in closed source programs.  The book is conceptually accessible to an individual with some knowledge of secure programming and vulnerabilities.<br />
Rating: 5 / 5</p>
]]></content:encoded>
	</item>
</channel>
</rss>
