Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
20 used & new from $49.95

Have one to sell? Sell yours here
 
   
Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy)
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy) (Hardcover)

by Ari Takanen (Author), Jared DeMott (Author), Charlie Miller (Author)
Key Phrases: target monitoring, security metrics, replacing fear, Guard Malloc, Fuzzing Metrics, Evolutionary Fuzzing (more...)
3.0 out of 5 stars See all reviews (2 customer reviews)

List Price: $85.00
Price: $68.00 & this item ships for FREE with Super Saver Shipping. Details
You Save: $17.00 (20%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Monday, July 13? Choose One-Day Shipping at checkout. Details
13 new from $68.00 7 used from $49.95

Frequently Bought Together

Customers buy this book with Gray Hat Hacking, Second Edition: The Ethical Hacker's Handbook by Shon Harris

Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy) + Gray Hat Hacking, Second Edition: The Ethical Hacker's Handbook
  • This item: Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy) by Ari Takanen

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Gray Hat Hacking, Second Edition: The Ethical Hacker's Handbook by Shon Harris

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Open Source Fuzzing Tools

Open Source Fuzzing Tools

by Noam Rathaus; Gadi Evron
$53.95
Fuzzing: Brute Force Vulnerability Discovery

Fuzzing: Brute Force Vulnerability Discovery

by Michael Sutton
4.4 out of 5 stars (5)  $34.64
Hacking Wall Street: Attacks And Countermeasures

Hacking Wall Street: Attacks And Countermeasures

by Karlos Krinklebine
4.7 out of 5 stars (6)  $36.12
The CERT C Secure Coding Standard (SEI Series in Software Engineering)

The CERT C Secure Coding Standard (SEI Series in Software Engineering)

by Robert C. Seacord
4.0 out of 5 stars (1)  $49.04
The Mac Hacker's Handbook

The Mac Hacker's Handbook

by Charles Miller
4.2 out of 5 stars (4)  $31.49
Explore similar items

Editorial Reviews

Product Description
"A fascinating look at the new direction fuzzing technology is taking -- useful for both QA engineers and bug hunters alike!"

--Dave Aitel, CTO, Immunity Inc.

Learn the code cracker's malicious mindset, so you can find worn-size holes in the software you are designing, testing, and building. Fuzzing for Software Security Testing and Quality Assurance takes a weapon from the black-hat arsenal to give you a powerful new tool to build secure, high-quality software. This practical resource helps you add extra protection without adding expense or time to already tight schedules and budgets. The book shows you how to make fuzzing a standard practice that integrates seamlessly with all development activities.

This comprehensive reference goes through each phase of software development and points out where testing and auditing can tighten security. It surveys all popular commercial fuzzing tools and explains how to select the right one for a software development project. The book also identifies those cases where commercial tools fall short and when there is a need for building your own fuzzing tools.

About the Author
Ari Takanen is the chief technical officer at Codenomicon, a software fuzzing tool company. A noted speaker and author on software testing and security, he is a graduate of Finland's University of Oulo, where he did research with the university's Secure Programming Group.

Jared D. DeMott is a software vulnerability researcher, speaker, teacher, and author. He is a leading expert on fuzzing and fuzzing tools . He earned an M.S. in computer science from Johns Hopkins University and is a Ph.D. candidate at Michigan State University.

Charlie Miller is principal analyst at Independent Security Evaluators. Previously, he spent five years at the National Security Agency. He is probably best known as the first to publicly create a remote exploit against the iPhone. Dr. Miller is also a frequent speaker at major computer security conferences. He earned his Ph.D. from the University of Notre Dame.


Product Details

  • Hardcover: 287 pages
  • Publisher: Artech House Publishers; 1 edition (June 30, 2008)
  • Language: English
  • ISBN-10: 1596932147
  • ISBN-13: 978-1596932142
  • Product Dimensions: 10.2 x 7.2 x 0.8 inches
  • Shipping Weight: 1.6 pounds (View shipping rates and policies)
  • Average Customer Review: 3.0 out of 5 stars See all reviews (2 customer reviews)
  • Amazon.com Sales Rank: #595,489 in Books (See Bestsellers in Books)

Inside This Book (learn more)

What Do Customers Ultimately Buy After Viewing This Item?

Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy)
60% buy the item featured on this page:
Fuzzing for Software Security Testing and Quality Assurance (Artech House Information Security and Privacy) 3.0 out of 5 stars (2)
$68.00
Fuzzing: Brute Force Vulnerability Discovery
15% buy
Fuzzing: Brute Force Vulnerability Discovery 4.4 out of 5 stars (5)
$34.64
Gray Hat Python: Python Programming for Hackers and Reverse Engineers
13% buy
Gray Hat Python: Python Programming for Hackers and Reverse Engineers 4.0 out of 5 stars (6)
$26.37
The Shellcoder's Handbook: Discovering and Exploiting Security Holes
6% buy
The Shellcoder's Handbook: Discovering and Exploiting Security Holes 4.5 out of 5 stars (22)
$31.49

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.
(1)

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

2 Reviews
5 star:
 (1)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
3.0 out of 5 stars (2 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
2 of 3 people found the following review helpful:
5.0 out of 5 stars One of the Best Resources on Fuzzing by Highly Skilled ex-NSA Employees, August 7, 2008
Fuzzing generally involves testing the parameters of an application using random or specifically formatted randomized input to evaluate whether a given application crashes and/ or can be exploited. At least two of the authors have worked at the National Security Agency. Dr. Charlie Miller is well known for publishing an interesting article on the economics of the black market trading of security vulnerabilities (avaliable at weis2007.econinfosec.org/papers/29.pdf). Dr. Miller demonstrated the utility of the procedures discussed in this book at BlackHat 2008. This book provides insight into an area of research that is not usually publicly avaliable. The book details a number of open-source and commercially avaliable fuzzers and their relative reliability in finding bugs. Fuzzers are one of the most reliable methods for finding vulnerabilities in closed source programs. The book is conceptually accessible to an individual with some knowledge of secure programming and vulnerabilities.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
1.0 out of 5 stars Disappointing and a mess, June 16, 2009
The introduction to this book mentions its broken up history, being picked up and abandoned a couple times. It definitely shows in the writing, which is unfocused, choppy, and repetitive. Most of the first half is taken up with repetitive descriptions of the general software testing process. The second half contains a summary of one author's thesis on using evolutionary algorithms for fuzzing and the final author's use of various fuzzing tools to try to find hand-inserted vulnerabilities. While the latter half is better than the first, each topic is worthy of a single blog post. Given this book's price and the authors' reputations, I expected more.

At the same time, I read "Gray Hat Python" and it was enjoyable. Even though it had a much broader focus on other topics, it contained more hands-on info on fuzzing tools. I'm also interested in "Fuzzing: Brute Force Vulnerability Discovery", although I have not read it yet.

Don't waste your time on this book. Download the Sulley manual, read the slides from a few Blackhat talks, and you'll be at the state of the art for current fuzzing knowledge.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


   


Product Information from the Amapedia Community

Beta (What's this?)



Look for Similar Items by Category


Discover Oregon

Garmin Oregon at Amazon.com
You'll find that on the trail, the new Garmin Oregons exchange waypoints, tracks, and geocaches with other Oregon and Colorado units.

Shop all Garmin

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Dive into Summer Reading

Summer Reading for Kids and Teens
Don't even think about hitting the beach without browsing the books in our Summer Reading Store. Discover bestsellers, paperback picks, beach reads, and more terrific titles all summer long.
 

Free Shipping on Marpac SleepMate

Marpac Sleep Mate
Sleep tight with the Marpac SleepMate white noise machine. It's perfect for restless sleepers, children, students, apartment residents, and others. Best of all, it ships for free.

Shop now

 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates