Shaleen Jain

· 1 min read

VLC Media Player and Fuzz testing

<p>Software bugs and vulnerabilities can be difficult to detect and slow to find even when actively searched for by developers and users who usually look for superficial functional and visual bugs.</p> <p>In a large software especially those written in middle level languages like C/C++, security bugs and vulnerabilities can often be used to comprise the whole system. Mainly because memory management is left to the programmers of the individual software.</p> <p>One alternative to human Q&amp;A testing is to use automated software testing techniques like Fuzzing where random, invalid or unexpected data is provided as input to a computer program.</p> <span id="continue-reading"></span> <p>Fuzzing is often more cost-effective than systematic testing techniques<sup class="footnote-reference"><a href="#fn-cite_report_random_testing">1</a></sup>. High profile CVE’s such as <a rel="noopener nofollow noreferrer external" target="_blank" href="https://en.wikipedia.org/wiki/Heartbleed">Heartbleed</a> in April 2014 and <a rel="noopener nofollow noreferrer external" target="_blank" href="https://en.wikipedia.org/wiki/Shellshock_(software_bug)">Shellshock</a> in September 2014 could have easily been found with fuzzing<sup class="footnote-reference"><a href="#fn-cite_heartbleed">2</a></sup> <sup class="footnote-reference"><a href="#fn-cite_shellshock">3</a></sup>.</p> <p>Media processing is always a complex task and usually contain lots of security and stability issues, take <a rel="noopener nofollow noreferrer external" target="_blank" href="https://en.wikipedia.org/wiki/Stagefright_%28bug%29">Stagefright</a> or <a rel="noopener nofollow noreferrer external" target="_blank" href="https://security.googleblog.com/2014/01/ffmpeg-and-thousand-fixes.html">FFmpeg and a thousand fixes</a>, for example.</p> <p><strong>Fuzzing VLC</strong>, the most popular desktop and mobile media player should now seem like a no-brainer.</p> <p>Indeed, this was one of the project ideas and my proposal to VideoLAN for Fuzz testing VLC as part of <abbr title="Google Summer of Code">GSoC</abbr> 2017. VideoLAN accepted my <a rel="noopener nofollow noreferrer external" target="_blank" href="https://summerofcode.withgoogle.com/projects/#5893995166171136">proposal</a> and invited me to their office in Paris for a “GSoC conference” to discuss and help setting up the project and get me started.</p> <div class="footnote-definition" id="fn-cite_report_random_testing"><sup class="footnote-definition-label">1</sup> <p><a rel="noopener nofollow noreferrer external" target="_blank" href="http://dl.acm.org/citation.cfm?id=802530">“A report on random testing”</a></p> </div> <div class="footnote-definition" id="fn-cite_heartbleed"><sup class="footnote-definition-label">2</sup> <p><a rel="noopener nofollow noreferrer external" target="_blank" href="https://blog.hboeck.de/archives/868-How-Heartbleed-couldve-been-found.html">“How Heartbleed could’ve been found (in English)”</a></p> </div> <div class="footnote-definition" id="fn-cite_shellshock"><sup class="footnote-definition-label">3</sup> <p><a rel="noopener nofollow noreferrer external" target="_blank" href="http://lcamtuf.blogspot.in/2014/10/bash-bug-how-we-finally-cracked.html">“Bash bug: the other two RCEs, or how we chipped away at the original fix (CVE-2014-6277 and ’78)”</a></p> </div>
Liked this article? Share this with others

Got any questions or comments? Drop me a message on Twitter @shalzzj

Sign up for my newsletter to be the first to know about a new post