Practical Fuzzing
暫譯: 實用模糊測試
Hart, Rowan
- 出版商: No Starch Press
- 出版日期: 2026-06-23
- 售價: $2,730
- 貴賓價: 9.5 折 $2,593
- 語言: 英文
- 頁數: 600
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1718504586
- ISBN-13: 9781718504585
-
相關分類:
Penetration-test
海外代購書籍(需單獨結帳)
商品描述
A hands-on, from-first-principles guide to building a modern, research-grade fuzzer you fully understand and control. Written for vulnerability researchers, security engineers, and tool builders who want to go beyond running AFL and actually own the techniques behind real bug discovery. Fuzzers find the bugs that everyone else misses. But most practitioners treat fuzzing as a black box: point a tool at a binary, hope for crashes, and pray something interesting comes out. Practical Fuzzing tears that mindset apart. Instead of running someone else's fuzzer, you build your own--step by step, from historical techniques to the modern coverage-guided engines used in serious research. Along the way, you'll apply your fuzzer to real software, generate real crashes, triage failures, minimize inputs, and learn how cutting-edge fuzzers evolve. By the end, you won't just know how fuzzing works. You'll have a working, extensible fuzzer you can tune, experiment with, and adapt for anything from userland binaries to kernels and emulated systems. You'll also gain the research literacy needed to understand and implement new ideas as the field advances. This is the book to read if you want to stop being a fuzzing user and start being a fuzzing engineer.
商品描述(中文翻譯)
一本實用的、從基本原則出發的指南,教你如何建立一個現代的、研究級的模糊測試器,讓你完全理解和控制。這本書是為了漏洞研究人員、安全工程師和工具開發者而寫,他們希望超越僅僅運行 AFL,真正掌握背後的技術,以發現真實的漏洞。
模糊測試器能找到其他人錯過的漏洞。但大多數從業者將模糊測試視為一個黑箱:將工具指向一個二進位檔,期待崩潰,並祈禱能有有趣的結果。 實用模糊測試 會打破這種思維模式。你不再是運行別人的模糊測試器,而是一步一步地建立自己的模糊測試器——從歷史技術到現代的覆蓋引導引擎,這些都是在嚴肅研究中使用的。在這個過程中,你將把你的模糊測試器應用於真實軟體,生成真實的崩潰,進行故障分類,最小化輸入,並學習尖端模糊測試器的演變。 到最後,你不僅會知道模糊測試是如何運作的。你將擁有一個可運作的、可擴展的模糊測試器,你可以調整、實驗,並適應從用戶空間二進位檔到內核和模擬系統的任何東西。你還將獲得研究素養,以理解和實施隨著領域進步的新想法。 如果你想停止成為模糊測試的使用者,開始成為模糊測試的工程師,這就是你該閱讀的書。作者簡介
Rowan Hart is a Security Engineer for Windows at Microsoft and previously worked on firmware and kernel fuzzing at Intel. He has also served as a vulnerability researcher at multiple government contractors. He holds an MS in Computer Science from Purdue University, where he focused on fuzzing and program analysis, and spent years competing in offensive Capture the Flag teams. When he's not building security tools, he's snowboarding, mountain biking, or climbing in Oregon.
作者簡介(中文翻譯)
Rowan Hart 是微軟 Windows 的安全工程師,之前在英特爾從事韌體和核心模糊測試。他也曾在多家政府承包商擔任漏洞研究員。他擁有普渡大學的計算機科學碩士學位,專注於模糊測試和程式分析,並花了數年時間參加攻擊性 Capture the Flag 團隊的競賽。當他不在開發安全工具時,他會在俄勒岡州滑雪、騎山地車或攀岩。