Перейти к содержимому

Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)

LiveOverflow

0:00 / 0:00

Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)

77 002 просмотра · 2 года назад
LiveOverflow
944 тыс. подписчиков
77 002 просмотра · 2 года назад
A guide on how to do fuzzing with AFL++ in an attempt to rediscover the libwebp vulnerability CVE-2023-4863 that was used to hack iPhones. LEARN ON HEXTREE (ad) Learn hacking on Hextree: https://www.hextree.io/ Join the Hextree Discord:   / discord   Watch webp Part 1:    • A Vulnerability to Hack The World - CVE-20...   Sudo Vulnerability Series:    • Sudo Vulnerability Walkthrough   Docker Video:    • How Docker Works - Intro to Namespaces   OSS-Fuzz: https://github.com/google/oss-fuzz OSS-Fuzz libwebp coverage: https://storage.googleapis.com/oss-fu... AFLplusplus: https://github.com/AFLplusplus/AFLplu... vanhauser's blog: https://www.srlabs.de/blog-post/advan... vanhauser/thc on twitter:   / hackerschoice   AFLpluslus Persistent Mode: https://github.com/AFLplusplus/AFLplu... Grab the code: https://github.com/LiveOverflow/webp-... CHAPTERS 00:00 - Intro 00:36 - How to Learn About Fuzzing? 02:36 - Setting Up Fuzzing With AFL++ 04:53 - My Docker Workflow for Fuzzing 06:35 - AFL++ Different Coverage Strategies 09:50 - Start the libwebp Fuzzing Campaign 11:58 - Adjusting the Fuzzer 13:45 - Why Don't We Find a Crash? 15:49 - Fuzzing with AFL++ Persistent Mode 19:47 - Persistent Mode Fuzzing Results 20:46 - Finding the Vulnerability in 8s SUPPORT Per video:   / liveoverflow   Per month:    / @liveoverflow   Buy my handwriting font (ad): https://shop.liveoverflow.com/ WATCH, FOLLOW & READ Second channel:    / liveunderflow   Twitch:   / liveoverflow   Twitter:   / liveoverflow   Instagram:   / liveoverflow   TikTok:   / liveoverflow_   LiveOverflow blog: https://liveoverflow.com/ Hextree blog (ad): https://www.hextree.io/blog #BrowserSecurity #SecurityResearch #LiveOverflow (ad) LiveOverflow YouTube channel is supported by advertisement and product placement.