Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-10 Thread Malte Timmermann
Hi Marc, On 05.10.2011 14:55, Marc-André Laverdière wrote: Why bother about this? Why not use what's available out there? Well... - Fuzzgrind isn't well documented and won't work out of the box, - zzuf has too many bells and whistles, and won't guarantee that every byte has been messed up wi

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-10 Thread Michael Meeks
Hi Marc, On Mon, 2011-10-10 at 15:08 +0530, Marc-André Laverdière wrote: > I have been struggling along the way and eventually put together this > small starting point... What do you think about it? Looks fun :-) I guess it is necessary to have a separate remote-control process if we want

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-10 Thread Marc-André Laverdière
Hello everyone, I have been struggling along the way and eventually put together this small starting point... What do you think about it? Marc-André Laverdière Software Security Scientist Innovation Labs, Tata Consultancy Services Hyderabad, India On 10/07/2011 01:38 PM, Michael Meeks wrote: >

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-07 Thread Michael Meeks
On Fri, 2011-10-07 at 10:53 +0530, Marc-André Laverdière wrote: > I'm not thrilled with the idea of so much process creation and overhead > (think Valgrind) for running a somewhat short test over and over again. Certainly; the linking / bootstrapping overhead is rather substantial in comp

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-06 Thread Marc-André Laverdière
Thanks for your feedback. I would really really like #1, but I'm not knowledgeable enough right now to do that. If (God willing), I'm starting that PhD soon, I might just be able to do that blindfolded a year from now :) For #2, I would like to have a tool generate the format handled by reading o

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-05 Thread Huzaifa Sidhpurwala
On 10/05/2011 06:41 PM, Caolán McNamara wrote: caolanm->huzaifas: any advice ? Nice to see the work you have been doing here! To share some opinion about the my work which lead me to the discovery of CVE-2011-2713. 1. There is no right or wrong approach here. A good approach would be the o

Re: [Libreoffice] RFC: Idea for fuzz-testing filters

2011-10-05 Thread Caolán McNamara
On Wed, 2011-10-05 at 18:25 +0530, Marc-André Laverdière wrote: > Hi everyone, > > Before I start writing code, I wanted to get the input of more > experienced developers. > > Why bother about this? Why not use what's available out there? Well... > - Fuzzgrind isn't well documented and won't wor