Fuzzing or fuzz testing is an automated software black box testing technique that evaluates the program's reaction to providing invalid, unexpected, or random data as inputs to a computer program.
Created by Barton Miller
发布于 September 1988
OSS-Fuzz - continuous fuzzing for open source software.
翻译 - OSS-Fuzz-开源软件的连续模糊测试。
#前端开发#Monkey testing library for web apps and Node.js
the champagne of beta embedded databases
翻译 - Beta嵌入式数据库的香槟
You Know, For WEB Fuzzing ! 日站用的字典。
Hypothesis is a powerful, flexible, and easy to use library for property-based testing.
翻译 - 假设是功能强大,灵活且易于使用的库,用于基于属性的测试。
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
翻译 - 简单的脚本进行全面侦察
syzkaller is an unsupervised coverage-guided kernel fuzzer
翻译 - syzkaller是不受监督的,覆盖率指导的内核模糊器
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
翻译 - afl ++具有社区补丁,AFLfast电源计划,qemu 3.1升级+ laf-intel支持,MOpt mutators,InsTrim工具,unicorn_mode,Redqueen等更多功能!
#Awesome#A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Developme...
Scalable fuzzing infrastructure.
翻译 - 可扩展的模糊测试基础架构。
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
翻译 - 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动
Property based testing framework for JavaScript (like QuickCheck) written in TypeScript
#安全#A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
翻译 - Burpsuite入侵者有效负载,BurpBounty有效负载,模糊列表,恶意文件上传以及网络渗透测试方法和清单的集合。
An step by step fuzzing tutorial. A GitHub Security Lab initiative
#Awesome#A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
翻译 - 一组很棒的 API 安全工具和资源。
A high performance offensive security tool for reconnaissance and vulnerability scanning