Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
LiveOverflow
0:00 / 0:00
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
77 002 просмотра · 2 года назад
LiveOverflow
944 тыс. подписчиков
77 002 просмотра · 2 года назад
A guide on how to do fuzzing with AFL++ in an attempt to rediscover the libwebp vulnerability CVE-2023-4863 that was used to hack iPhones.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Join the Hextree Discord: / discord
Watch webp Part 1: • A Vulnerability to Hack The World - CVE-20...
Sudo Vulnerability Series: • Sudo Vulnerability Walkthrough
Docker Video: • How Docker Works - Intro to Namespaces
OSS-Fuzz: https://github.com/google/oss-fuzz
OSS-Fuzz libwebp coverage: https://storage.googleapis.com/oss-fu...
AFLplusplus: https://github.com/AFLplusplus/AFLplu...
vanhauser's blog: https://www.srlabs.de/blog-post/advan...
vanhauser/thc on twitter: / hackerschoice
AFLpluslus Persistent Mode: https://github.com/AFLplusplus/AFLplu...
Grab the code: https://github.com/LiveOverflow/webp-...
CHAPTERS
00:00 - Intro
00:36 - How to Learn About Fuzzing?
02:36 - Setting Up Fuzzing With AFL++
04:53 - My Docker Workflow for Fuzzing
06:35 - AFL++ Different Coverage Strategies
09:50 - Start the libwebp Fuzzing Campaign
11:58 - Adjusting the Fuzzer
13:45 - Why Don't We Find a Crash?
15:49 - Fuzzing with AFL++ Persistent Mode
19:47 - Persistent Mode Fuzzing Results
20:46 - Finding the Vulnerability in 8s
SUPPORT
Per video: / liveoverflow
Per month: / @liveoverflow
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: / liveunderflow
Twitch: / liveoverflow
Twitter: / liveoverflow
Instagram: / liveoverflow
TikTok: / liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BrowserSecurity #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.