Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.
How a stack buffer overflow was found in the compression utility dact using AFL and AddressSanitizer. Root-cause analysis of a file_extd_urls array overflow triggered by a crafted DACT header.