What You Need to Know Before
You Start
Starts 8 June 2025 23:28
Ends 8 June 2025
00
days
00
hours
00
minutes
00
seconds
Finding 0-Days in PHP Apps with Coverage-guided Fuzzing - What The PHUZZ?!
Discover how PHUZZ, an open-source prototype, enables coverage-guided fuzz testing for PHP web applications, outperforming popular scanners in detecting vulnerabilities and uncovering CVEs in WordPress plugins.
nullcon
via YouTube
nullcon
2544 Courses
38 minutes
Optional upgrade avallable
Not Specified
Progress at your own speed
Free Video
Optional upgrade avallable
Overview
Discover how PHUZZ, an open-source prototype, enables coverage-guided fuzz testing for PHP web applications, outperforming popular scanners in detecting vulnerabilities and uncovering CVEs in WordPress plugins.
Syllabus
- Introduction to Coverage-guided Fuzzing
- Overview of PHUZZ
- Setting Up the Environment
- Deep Dive into PHUZZ Architecture
- Leveraging PHUZZ for Vulnerability Detection
- Comparing PHUZZ with Popular Vulnerability Scanners
- Advanced PHUZZ Configuration
- Best Practices for Effective Fuzz Testing
- Hands-on Lab: Fuzzing a PHP Web Application
- Conclusion and Future Trends
- Additional Resources
What is Fuzzing?
Types of Fuzzing Techniques
Introduction to Coverage-guided Fuzzing
What is PHUZZ?
Features of PHUZZ
How PHUZZ Differs from Other Fuzzers
Required Tools and Software
Configuring PHUZZ for PHP Applications
Integrating PHUZZ with Existing Development Workflows
Core Components of PHUZZ
How Coverage-guided Fuzzing Works in PHUZZ
Analyzing PHP Application Coverage
Identifying Common Vulnerabilities in PHP Apps
Using PHUZZ for Real-world Vulnerability Discovery
Case Studies: CVEs Found in WordPress Plugins
Review of Traditional Scanners
Performance Benchmarking: PHUZZ vs Other Tools
Understanding the Advantages of PHUZZ
Fine-tuning Fuzzing Parameters
Customizing PHUZZ for Specific Applications
Developing Robust Test Cases
Avoiding Common Pitfalls in Fuzzing
Documenting and Reporting Findings
Setting Up a Target PHP Application
Running PHUZZ on the Application
Analyzing Results and Identifying Exploits
Key Takeaways
Future Trends in Fuzz Testing and Vulnerability Detection
Recommended Reading and Tools
Joining the PHUZZ Community for Updates and Support
Subjects
Programming