{"repo":"google/honggfuzz","free":true,"listed":false,"github":"https://github.com/google/honggfuzz","clone":"git clone https://github.com/google/honggfuzz.git","description":"Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)","language":"C","stars":3372,"topics":["fuzzing","security","c"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Honggfuzz A security-oriented, feedback-driven, evolutionary fuzzer. Honggfuzz is a general-purpose fuzzer that uses code coverage (software and hardware-based) to find bugs. It is multi-process, multi-threaded, and supports persistent fuzzing for extreme speed. Key Features Fast : Multi-process and multi-threaded engine. unlocking full CPU potential. Persistent Fuzzing : Test APIs directly in-process with iteration speeds up to 1M/sec. Feedback-Driven : Uses hardware (Intel BTS/PT) and software code coverage to evolve inputs. Easy : Can start with an empty corpus and automatically build a valid input set. Deep Monitoring : Uses low-level APIs ( ptrace ) to detect hijacked signals and hidden crashes. Broad Support : Linux, macOS, Android, NetBSD, FreeBSD, and Windows (Cygwin). Installation Dependencies Linux (Ubuntu/Debian) macOS Requires Xcode (10.8+) and libblocksruntime . Build Usage 1. Compile Target Use the provided compiler wrappers to automatically add instrumentation: 2. Run Fuzzer Point it to an input corpus directory (can be empty) and your binary: Note: FILE is a placeholder for the input filename generated by honggfuzz. For advanced examples (Apache, OpenSSL, BIND, etc.), check the examples/ directory. See USAGE.md for detailed options. Trophies Honggfuzz has discovered major security vulnerabilities in critical software. HTTP & Servers Apache HTTPD : CVE-2017-7659 (mod http2 remote crash) CVE-2017-9789 (Use-after-free) CVE-2018-1301, CVE-2018-1302, CVE-2018-1303 ","default_branch":null,"files":null,"tree":[],"storefront":"/r/google","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/google/honggfuzz/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}