<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fuzzing talk at the Mozilla Summit</title>
	<atom:link href="http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<lastBuildDate>Fri, 09 Sep 2011 05:56:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Darren</title>
		<link>http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/comment-page-1/#comment-9011</link>
		<dc:creator>Darren</dc:creator>
		<pubDate>Tue, 14 Dec 2010 23:31:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=594#comment-9011</guid>
		<description>We&#039;ve got a pretty cool resource we&#039;ve put together for the security community as a means to learn how to use fuzzers and do automation. 

It&#039;s an application specifically built to contain vulnerabilities discoverable by fuzzing techniques...and an in-depth article showing how to do it. We&#039;d love for you to feature it if you think your readers would like it: http://resources.infosecinstitute.com/intro-to-fuzzing/</description>
		<content:encoded><![CDATA[<p>We&#8217;ve got a pretty cool resource we&#8217;ve put together for the security community as a means to learn how to use fuzzers and do automation. </p>
<p>It&#8217;s an application specifically built to contain vulnerabilities discoverable by fuzzing techniques&#8230;and an in-depth article showing how to do it. We&#8217;d love for you to feature it if you think your readers would like it: <a href="http://resources.infosecinstitute.com/intro-to-fuzzing/" rel="nofollow">http://resources.infosecinstitute.com/intro-to-fuzzing/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonym</title>
		<link>http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/comment-page-1/#comment-7452</link>
		<dc:creator>Anonym</dc:creator>
		<pubDate>Wed, 18 Aug 2010 01:47:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=594#comment-7452</guid>
		<description>This is an awesome presentation.  Thanks!

I thought I&#039;d share a pointer to the Lithium test case minimization tool, for others, since it turns out to be surprisingly hard to Google. :-)  Here&#039;s what I found:

http://www.squarefree.com/lithium/</description>
		<content:encoded><![CDATA[<p>This is an awesome presentation.  Thanks!</p>
<p>I thought I&#8217;d share a pointer to the Lithium test case minimization tool, for others, since it turns out to be surprisingly hard to Google. :-)  Here&#8217;s what I found:</p>
<p><a href="http://www.squarefree.com/lithium/" rel="nofollow">http://www.squarefree.com/lithium/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/comment-page-1/#comment-7182</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Fri, 16 Jul 2010 15:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=594#comment-7182</guid>
		<description>My DOM fuzzer doesn&#039;t specifically look for Same Origin Policy bypasses, but it has triggered assertion failures that indicated bugs in privilege- and wrapper-related code.  Assertions are great.</description>
		<content:encoded><![CDATA[<p>My DOM fuzzer doesn&#8217;t specifically look for Same Origin Policy bypasses, but it has triggered assertion failures that indicated bugs in privilege- and wrapper-related code.  Assertions are great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Soroush Dalili</title>
		<link>http://www.squarefree.com/2010/07/14/fuzzing-talk-at-the-mozilla-summit/comment-page-1/#comment-7151</link>
		<dc:creator>Soroush Dalili</dc:creator>
		<pubDate>Fri, 16 Jul 2010 08:41:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=594#comment-7151</guid>
		<description>I&#039;m waiting to see your new fuzzing technique. I know that there are several DOM fuzzers which iterate all objects and call the functions and fuzz them. Is there anything new in your technique? Is it intelligent enough to detect Same Origin Policy bypass vulnerabilities as well as the memory corruptions? Thanks for sharing the information in advance.

Cheers,
Soroush
Soroush.secproject.com/blog/</description>
		<content:encoded><![CDATA[<p>I&#8217;m waiting to see your new fuzzing technique. I know that there are several DOM fuzzers which iterate all objects and call the functions and fuzz them. Is there anything new in your technique? Is it intelligent enough to detect Same Origin Policy bypass vulnerabilities as well as the memory corruptions? Thanks for sharing the information in advance.</p>
<p>Cheers,<br />
Soroush<br />
Soroush.secproject.com/blog/</p>
]]></content:encoded>
	</item>
</channel>
</rss>

