Security

AFL++ – fuzzing framework

American Fuzzy Lop plus plus (AFL++) is a security-oriented fuzzer that employs a novel type of compile-time instrumentation and genetic algorithms to automatically discover clean, interesting test cases that trigger new internal states in the targeted binary.

Fuzzing (sometimes known as fuzz testing) is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program.

AFL++ is the daughter of the American Fuzzy Lop fuzzer.

This is free and open source software.

Key Features

  • AFLfast’s power schedules.
  • MOpt mutator.
  • InsTrim, a very effective CFG llvm_mode instrumentation implementation for large targets.
  • afl-fuzz Python mutator module and llvm_mode whitelist support.
  • Custom mutator by a library (instead of Python)
  • Unicorn mode which allows fuzzing of binaries from completely different pla.tforms.
  • LAF-Intel or CompCov support for llvm_mode, qemu_mode and unicorn_mode.
  • NeverZero patch for afl-gcc, llvm_mode, qemu_mode and unicorn_mode which prevents a wrapping map value to zero, increases coverage.
  • Persistent mode and deferred forkserver for qemu_mode.
  • Win32 PE binary-only fuzzing with QEMU and Wine.
  • Radamsa mutator (enable with -R to add or -RR to run it exclusively).
  • QBDI mode to fuzz android native libraries via QBDI framework.
  • The new CmpLog instrumentation for LLVM and QEMU.
  • LLVM mode Ngram coverage.

The AFL++ fuzzing framework includes the following:

  • A fuzzer with many mutators and configurations: afl-fuzz.
  • Different source code instrumentation modules: LLVM mode, afl-as, GCC plugin.
  • Different binary code instrumentation modules: QEMU mode, Unicorn mode, QBDI mode.
  • Utilities for testcase/corpus minimization: afl-tmin, afl-cmin.
  • Helper libraries: libtokencap, libdislocator, libcompcov.

Website: aflplus.plus
Support: GitHub Code Repository
Developer: van Hauser, hexcoder, and many other contributors
License: Apache License 2.0

AFL++ is written in C and C++. Learn C with our recommended free books and free tutorials. Learn C++ with our recommended free books and free tutorials.


Related Software

Vulnerability Analysis Tools
BeEFThe Browser Exploitation Framework
syzkallerUnsupervised, coverage-guided kernel fuzzer
pocsuite3Remote vulnerability testing framework
AFL++Security-oriented fuzzer
JazzerCoverage-guided, in-process fuzzer for the Java Virtual Machine
RoninRuby toolkit for security research and development
KanhaWeb-app pentesting suite
simple fuzzerA fuzzer with two network modes of operation
DoonaFork of the Bruteforce Exploit Detector Tool

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our carefully curated directory of recommended free and open source software, covering every major software category.

The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more.

Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form.
Subscribe

Please read our Comment Policy before commenting.

Notify of
guest
0 Comments
Oldest
Newest Most Voted