+
+

Related Products

  • cside
    25 Ratings
    Visit Website
  • Bitdefender Ultimate Small Business Security
    3 Ratings
    Visit Website
  • ManageEngine ADManager Plus
    632 Ratings
    Visit Website
  • Chainguard
    49 Ratings
    Visit Website
  • Cerberus FTP Server
    159 Ratings
    Visit Website
  • EasyDMARC
    201 Ratings
    Visit Website
  • ToogleBox
    75 Ratings
    Visit Website
  • Letsignit
    185 Ratings
    Visit Website
  • ManageEngine OpManager
    1,660 Ratings
    Visit Website
  • NINJIO
    415 Ratings
    Visit Website

About

FuzzDB was created to increase the likelihood of finding application security vulnerabilities through dynamic application security testing. It's the first and most comprehensive open dictionary of fault injection patterns, predictable resource locations, and regex for matching server responses. FuzzDB contains comprehensive lists of attack payload primitives for fault injection testing. These patterns, categorized by the attack and where appropriate platform type, are known to cause issues like OS command injection, directory listings, directory traversals, source exposure, file upload bypass, authentication bypass, XSS, HTTP header crlf injections, SQL injection, NoSQL injection, and more. For example, FuzzDB catalogs 56 patterns that can potentially be interpreted as a null byte and contains lists of commonly used methods and name-value pairs that trigger debug modes.

About

Fuzzing is a powerful strategy to find bugs in software. The idea is quite simple, which is to generate a large number of randomly malformed inputs for the software to parse and see what happens. If the program crashes then something is likely wrong. While fuzzing is a well-known strategy, it is surprisingly easy to find bugs, often with security implications, in widely used software. Memory access errors are the errors most likely to be exposed when fuzzing software that is written in C/C++. While they differ in the details, the core problem is often the same, the software reads or writes to the wrong memory locations. A modern Linux or BSD system ships a large number of basic tools that do some kind of file displaying and parsing. In their current state, most of these tools are not suitable for untrusted inputs. On the other hand, we have powerful tools these days that allow us to find and analyze these bugs.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Anyone requiring a security scanner solution to test their application protocols

Audience

Developers and anyone in need of a tool to improve the security of their software applications

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

Free
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

FuzzDB
github.com/fuzzdb-project/fuzzdb

Company Information

Fuzzing Project
fuzzing-project.org

Alternatives

Alternatives

API Fuzzer

API Fuzzer

Fuzzapi
go-fuzz

go-fuzz

dvyukov
ClusterFuzz

ClusterFuzz

Google
CI Fuzz

CI Fuzz

Code Intelligence

Categories

Categories

Integrations

BlackArch Linux
C
C++
NoSQL
OWASP ZAP

Integrations

BlackArch Linux
C
C++
NoSQL
OWASP ZAP
Claim FuzzDB and update features and information
Claim FuzzDB and update features and information
Claim Fuzzing Project and update features and information
Claim Fuzzing Project and update features and information