Fuzzing

Brain dumps on fuzzing, the book and security in general.

Michael Sutton Banner Ad?

I was browsing around looking for various blog and news hits on the fuzzing book, when I came across the following on RedmondDeveloper:

Took me a few seconds to realize it wasn’t some random banner ad.

Last 5 posts by pamini

1 Comment so far

  1. Jason October 9th, 2007 12:16 pm

    Thats funny. Can Sulley be adjusted to look for your quotes out of context to prevent you from showing up on a geico, or worse, a competitors product banner?

    …but seriously, you can grab my mugshot from Symantec’s CIO digest article (http://www.symantec.com/ciodigest/articles/200701/by_the_numbers.html) and use this quote if you so choose: I’ve got a copy. After reading the it in it’s entirety, I think it will need to be on the shelf as part of any security professional’s library. I’m not a programmer, nor do I manage programmers directly, so I can’t speak to the direct impact the practice of “fuzzing” may or may not have on an application’s ultimate success. I do, however, speak to them regularly and I need to know this stuff even if it hurts my brain to be pouring over it, knowing that the chances of me actually using the tools or frameworks discussed in the book are slim to none. I can speak first handed from the vantage point of a CISO, it is essential that executives begin to understand not only what “fuzzing” is, but why we need it, and more importantly, where it fits in the evangelical world of information security.

Leave a reply