16 December 2010 | 10,674 views

Honggfuzz – Simple Command Line Software Fuzzing Tool

Acunetix Web Application Security

Honggfuzz is a general-purpose fuzzing tool. Given a starting corpus of test files, Hongfuzz supplies and modifies input to a test program and utilize the ptrace() API/POSIX signal interface to detect and log crashes.

Basically it’s a simple, easy to use via command-line interface, providing nice analysis of software crashes in a simple form of file names.

It has been used to find a few (possibly exploitable) bugs in some major software packages including freetype2, librsvg and libtiff.

Features

  • Easy setup: No complicated configuration files or setup necessary — Hongfuzz can be run directly from the command line.
  • Fast: Multiple Hongfuzz instances can be run simultaneously for more efficient fuzzing.
  • Powerful analysis capabilities: Hongfuzz will use the most powerful process state analysis (e.g. ptrace) interface under a given OS.

You can download Honggfuzz here:

honggfuzz-0.1.tgz

Or read more here.





                

Recent in Exploits/Vulnerabilities:
- Royal Canadian Mounted Police Arrest Heartbleed Hacker
- Heartbleed Bug SSL Vulnerability – Everything You Need To Know
- Oracle Java Cloud Service Vulnerabilities Publicly Disclosed

Related Posts:
- Browser Fuzzer 3 (bf3) – Comprehensive Web Browser Fuzzing Tool
- fm-fsf – Freakin’ Simple Fuzzer – Cross Platform Fuzzing Tool
- Keep on Fuzzing! Advice

Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 225,427 views
- AJAX: Is your application secure enough? - 118,959 views
- eEye Launches 0-Day Exploit Tracker - 84,997 views

Low-cost VPS Hosting

2 Responses to “Honggfuzz – Simple Command Line Software Fuzzing Tool”

  1. Hackito Fan 16 December 2010 at 10:53 am Permalink

    What’s the main difference with zzuf command line fuzzer? Something it does better?

    • Darknet 17 December 2010 at 8:12 am Permalink

      How about you compare them both and let us know :)