YoVDO

Fuzzing Android - A Recipe for Uncovering Vulnerabilities Inside System Components in Android

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Fuzzing Courses Vulnerability Research Courses

Course Description

Overview

Explore a powerful fuzzing approach for uncovering vulnerabilities in Android's core system components in this 45-minute Black Hat conference talk. Delve into the general methodology and its practical application across multiple real-life Android OS targets, including the Stagefright framework, mediaserver process, APK install process, installd daemon, dex2oat, and ART. Learn about the fuzzing process, encompassing data/seed generation, test case execution, logging, and triage mechanisms. Discover strategies for addressing challenges such as bug reproducibility, identifying unique issues, and prioritizing based on severity. Gain insights into the development of specialized tools using this methodology, with a focus on innovative technical details. Examine the impressive results achieved, including thousands of crashes discovered, numerous unique issues identified, and six CVE entries released by Google.

Syllabus

Fuzzing Android: A Recipe For Uncovering Vulnerabilities Inside System Components In Android


Taught by

Black Hat

Related Courses

Security Principles
(ISC)² via Coursera
A Strategic Approach to Cybersecurity
University of Maryland, College Park via Coursera
FinTech for Finance and Business Leaders
ACCA via edX
Access Control Concepts
(ISC)² via Coursera
Access Controls
(ISC)² via Coursera