If you are wondering what it takes to get published in phrack click through to the CFP for areas of interest but tl:dr
the requirements are:
offensive security research
10-20pgs deep dive on internals/theory
Proven practical demo and source code snapshot. submissions@phrack.org
08.03.2026 22:49
π 1
π 1
π¬ 0
π 0
Perhaps they mean to cite Thayer et. al. "Software Reliability"? It has some claims like this.
24.02.2026 21:54
π 1
π 0
π¬ 0
π 0
Love visualizable #fuzzer progress :)
23.02.2026 01:41
π 2
π 0
π¬ 0
π 0
100,000 fuzz iterations. I'd say this part of the system works :)
21.02.2026 06:28
π 30
π 2
π¬ 2
π 0
Awesome Fuzzing
Zulip for the AFL++ and broader fuzzing community.
Wanna learn more about #fuzzing? The AFL++ community has moved to Zulip: fuzz.zulipchat.com
Come join us!
21.02.2026 21:09
π 3
π 2
π¬ 0
π 0
whoever did this deserves a medal or something
20.02.2026 18:52
π 26
π 7
π¬ 2
π 1
Andreas Zeller and PhD students
About time: A multi-celebration for becoming a member of Academia Europaea, my SIGSOFT Influential Educator Award, my 60th birthday, becoming an IEEE Fellow, _and_ getting the 2026 IEEE Harlan D. Mills Award. With cake and fizzy drinks!
16.02.2026 08:03
π 13
π 1
π¬ 0
π 0
The Fuzzing Book
Welcome to "The Fuzzing Book"! Software has bugs, and catching bugs can involve lots of effort. This book addresses this problem by automating software testing, specifically by generating tests autom...
Here are some other resources:
- www.fuzzingbook.org
- appsec.guide/docs/fuzzing/
Honestly there's a lot of different strategies. I really need to look at the current Arrow fuzzing properly at some point, it sounds like an interesting target.
12.02.2026 15:33
π 1
π 0
π¬ 0
π 0
Some good alternative oracles for fuzzing:
- differential fuzzing: compare two impls
- property fuzzing: check that a property holds
- metamorphic fuzzing: check that two semantically equivalent inputs have same outputs (requires metamorphic relations): www.jacarte.me/assets/pdf/w...
12.02.2026 15:30
π 0
π 0
π¬ 1
π 0
I'm hoping to soon start up a running list of fuzzer failures and lessons learned at fuzz.fail and maybe make some more guides on reasoning about fuzzer behaviour. Time will tell! I will be wrapping up my PhD in a few months and will take a break to work on such side projects. :)
12.02.2026 15:04
π 2
π 0
π¬ 0
π 0
Hello, I'm a PhD candidate at CISPA and I work on understanding theoretical limitations of fuzzing and improving empirical analysis. Most recently I've been working on analyzing input coverage strategies, new methods for comparing fuzzers, and grammar-based generation optimizations.
12.02.2026 15:02
π 0
π 0
π¬ 1
π 0
Alright fuzzing friends-
good time to reconnect and help each other fuzz harder better faster stronger
Reply with how long youβve been fuzzing, preferred fuzzing framework, how you approach writing a harness and validating results
#Fuzzing #PropertyTesting to help find each other
29.01.2026 03:51
π 7
π 1
π¬ 4
π 0
Ah, fuzzer findings are logarithmic with time: mboehme.github.io/paper/FSE20....
Making custom fuzzers and running them for ~30m intermittently is probably sufficient. This is, for example, what PCRE2 does with differential fuzzers: github.com/PCRE2Project...
Diff is not enabled in OSS-Fuzz.
12.02.2026 14:39
π 1
π 0
π¬ 1
π 0
OSS-Fuzz is... fine, but there are theoretical limitations to using the same set of fuzzers for all targets. Hopefully my mail answers this in greater detail.
11.02.2026 16:40
π 1
π 0
π¬ 1
π 0
I'm guessing I have to subscribe first, THEN send the email? I tried emailing without subscribing and I guess it piped them to null...
11.02.2026 16:37
π 0
π 0
π¬ 1
π 0
I sent a longer-form reply to this email list, hopefully it appears :)
11.02.2026 16:19
π 1
π 0
π¬ 1
π 0
Consider using LibAFL or building custom fuzzers for this kind of problem :) There are applications where program output is considered, e.g.: ieeexplore.ieee.org/document/103...
This is available in long form: queensu.scholaris.ca/server/api/c...
See (for similar strategies): www.fuzzingbook.org
11.02.2026 15:43
π 0
π 0
π¬ 0
π 0
Yes, there are many such metrics! But these are mostly in the literature as, so far, very few have been made that both meaningfully increases the insight we gain into the program and don't obliterate execution speed. e.g., value profile and "features" described in libFuzzer and Centipede.
11.02.2026 15:39
π 1
π 0
π¬ 1
π 0
GitHub - addisoncrump/sokoban-fuzz: Using fuzzing to find sokoban solutions.
Using fuzzing to find sokoban solutions. Contribute to addisoncrump/sokoban-fuzz development by creating an account on GitHub.
Heyo. You can find the fuzzer here: github.com/addisoncrump...
The TL;DR is that (1) there is a _mutation_ space reduction (i.e., no mutations that can't work or are destructive) and (2) input space reduction (only crate position + available crate movement); also: snapshot fuzzing!
11.02.2026 15:38
π 1
π 0
π¬ 0
π 0
β±οΈ 9 days until submission deadline (Dec 11, 23:59 AoE).
Organized by: @yannicnoller.bsky.social, @rohan.padhye.org, @ruijiemeng.bsky.social, and Laszlo (@lszekeres.bsky.social) Szekeres.
03.12.2025 10:59
π 4
π 5
π¬ 0
π 0
"every function accepts and returns the entire program state" type beat
21.11.2025 23:55
π 1
π 0
π¬ 0
π 0
Plakat mit Text:
"Dieses Jahr werden hunderte Millionen Computer dem geplanten VerschlieΓ zum Opfer fallen."
Poster, translated to English:
"This year, hundreds of millions of computers become victim to planned obsolescence."
Plakat mit Text:
"Software-Obsoleszenz ist das Thema des diesjΓ€hrigen Internationalen Reparaturtags, der im Saarland zum neunten Mal stattfindet.
Gemeinsam mit Expert:innen aus der Industrie mΓΆchten wir die ΓΆkologischen und sozialen Konsequenzen von absichtlich veralteten Produkten diskutieren, und ΓΌberlegen was wir dagegen tun kΓΆnnen."
Translated to English:
"Software Obsolescence is the topic of this year's International Repair Day, celebrated in Saarland for the 9th time.
Together with industry experts, we'll discuss the ecological and social impacts of products with intentionally shortened lifespans and what we can do about it."
At the bottom, the address is provided:
H'eck
RathausstraΓe 18
66125 SaarbrΓΌcken
And the date:
11 November, 2025
1700-1900
Cool event in #saarland about #software #obsolescence that my partner is helping to run :) Speakers from #KDE, #StopKillingGames, etc. The event will be mostly in German, but folks who aren't so confident in German should come along; most folks attending/speaking are also fluent in English.
09.11.2025 15:22
π 5
π 0
π¬ 0
π 0
Oh! Totally misread this tone lmao
02.11.2025 16:45
π 1
π 0
π¬ 0
π 0
Okay, but also look at how these folks have been treated in the past :p I'm not saying it's a good solution but it's a damn good way to get people who depend on libxml2 for financial gain to actually contribute back/assist in remediation rather than just yelling at the devs to do so
02.11.2025 12:14
π 3
π 0
π¬ 1
π 0
What is shallow to grammar fuzzers might not be shallow to byte mutator fuzzers e.g.
30.10.2025 17:10
π 2
π 0
π¬ 1
π 0
Ah yeah I'm just being argumentative lol
30.10.2025 17:08
π 1
π 0
π¬ 1
π 0
shallow to whom? π§
30.10.2025 17:00
π 0
π 0
π¬ 1
π 0
sadly, yes
Though, time-to-bug metrics are still super sparse and not necessarily reliable...
30.10.2025 16:59
π 1
π 0
π¬ 1
π 0
What the hell are we doing? Β· Addison Crump
Homepage for Addison Crump
Must-read for fuzzing folks (read: tooling/algorithms/academia) by Addison Crump
addisoncrump.info/research/wha...
26.10.2025 03:16
π 30
π 11
π¬ 1
π 1