Skip to content

Comment on Looking Back at Three Months of afl-fuzzparent

Comments

I don't see why you're singling out afl-fuzz when you can say the exact same thing for every automated penetration testing tool.

There's scores of Linux distributions dedicated to bundling as many security-related scripts as possible. If we're going to be talking about "utility to blackhatters", there's plenty of tools that have been around for longer and have been far more influential.

I'm singling out afl-fuzz because it seems to be so spectacularly successful. In fact, this blog post is all about how spectacularly successful it is. Maybe it isn't actually, compared to all those others tools I don't know about, but then maybe you could've just said that and skipped the sneering? I've been pretty forthcoming about my lack of security expertise, I'm just asking people like you an honest opinion.

Yes it was. It's safe to assume the "bad guys" have this stuff already, now the public gets to catch up.

Most automated penetration testing tools show what known vulnerabilities a target system has, and can help piece them together into a complete exploit: they do not find new bugs.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.