4f: The File Format Fuzzing Framework

Don't let your data go over to the Dark Side!


4f is a file format fuzzing framework. 4f uses modules which are specifications of the targeted binary or text file format that tell it how to fuzz the target application. If 4f detects a crash, it will log crucial information important for allowing the 4f user to reproduce the problem and also debugging information important to deciding the severity of the bug and its exploitability.

4f’s purpose is to find vulnerabilities in code that parses file formats including configuration files.

4f uses specialized modules for fuzzing code that interprets file formats. Several modules are included and more can be written to follow other file formats.

A module system is in place for fuzzing any file format you like as long as you know its specification

Custom debugger gathers crucial debugging information on crash, logs it, then continues fuzzing.

Usage


You can download 4f here:

4f.tar.gz

Or read more here.


Posted in: Exploits/Vulnerabilities, Programming

, , , , , ,

Recent in Exploits/Vulnerabilities:
- Apple Will Not Patch Windows QuickTime Vulnerabilities
- BADLOCK – Are ‘Branded’ Exploits Going Too Far?
- DROWN Attack on TLS – Everything You Need To Know

Related Posts:

Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 234,051 views
- AJAX: Is your application secure enough? - 119,981 views
- eEye Launches 0-Day Exploit Tracker - 85,452 views

Get 50% off your second year with our 2-year deal!


Comments are closed.