Skip to content
GitLab
Next
    • GitLab: the DevOps platform
    • Explore GitLab
    • Install GitLab
    • How GitLab compares
    • Get started
    • GitLab docs
    • GitLab Learn
  • Pricing
  • Talk to an expert
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
    Projects Groups Topics Snippets
  • Register
  • Sign in
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
    • Locked files
  • Issues 49,685
    • Issues 49,685
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,557
    • Merge requests 1,557
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Artifacts
    • Schedules
    • Test cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #10852
Closed
Open
Issue created Apr 02, 2019 by Fabio Busatto@bikebillyContributor

fuzz Libraries (code) in GitLab

Below list may need to be pared sown ad there is a different issue for API fuzzing

This issue should focus on NOT API fuzzing but code fuzzing

This is a list of software that we can consider when implementing GitLab fuzzing features.

  • American Fuzzy Lop: open-source
  • Beyond Security beSTORM: COTS with multiple protocol support similar to Peach or Synopsys
  • ForAllSecure MAYHEM: startup from DARPA Cyber Grand Challenge
  • Google OSS-Fuzz: Google hosted service/framework for evaluating open source projects
  • Grammatech CodeSonar: specifically the binary analysis/decompiler functionality which is part of their SAST
  • libFuzzer: open-source
  • Microsoft binskim: lightweight scanner that checks binary attributes and compiler settings
  • Microsoft Security Risk Detection: SaaS delivery of binary analysis
  • OpenRCE Sulley: open-source
  • Peach Tech Peach Fuzzer: COTS
  • Radamsa: open-source
  • Rogue Wave CodeDynamics: debugger with dynamic analysis for python and C/C++
  • Synopsys Defensics: COTS with multiple protocol support similar to beSTORM or Peach
  • Trail of Bits Manticore: open-source

Other tools available in https://www.owasp.org/index.php/Fuzzing#Fuzzing_tools.

The following page may contain information related to upcoming products, features and functionality. It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes. Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.

Edited Oct 13, 2021 by 🤖 GitLab Bot 🤖
Assignee
Assign to
Time tracking