Finding Zero-Day Vulnerabilities in Web Applications with Coverage-Guided Fuzzing - PHUZZ Framework
media.ccc.de via YouTube
PowerBI Data Analyst - Create visualizations and dashboards from scratch
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore coverage-guided fuzzing for PHP web applications in this one-hour conference talk from the 38th Chaos Communication Congress (38C3). Learn about PHUZZ, an academic fuzzing framework that outperforms traditional black-box vulnerability scanners in detecting web vulnerabilities. Discover how coverage-guided fuzzing, traditionally used for finding memory corruption bugs in binary applications, can be effectively applied to web application security testing. Understand the technical challenges of implementing coverage-guided fuzzing for web applications and see how PHUZZ successfully detects various vulnerability classes including SQLi, RCE, XSS, XXE, open redirection, insecure deserialization, and path traversal. Follow along as the framework's capabilities are demonstrated through real-world examples, including the discovery of over 20 potential security issues and two 0-day vulnerabilities in popular WordPress plugins. Gain insights into automated vulnerability discovery methods that offer a more cost-effective alternative to traditional security testing approaches like penetration testing and source code reviews.
Syllabus
38C3 - What the PHUZZ?! Finding 0-days in Web Applications with Coverage-guided Fuzzing
Taught by
media.ccc.de