LitMy.ru - литература в один клик

Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel (Early Access)

  • Добавил: literator
  • Дата: 30-08-2026, 17:53
  • Комментариев: 0

Название: Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel (Early Access)
Автор: Hamzeh Zawawy, Eugene Rodionov, Xuan Xing, Kris Alder, Cory Barker, Steven Moreland
Издательство: No Starch Press
Год: 2026
Страниц: 209
Язык: английский
Формат: pdf (true), epub
Размер: 10.1 MB

The operational playbook for fuzzing Android, from Binder services to the Linux kernel, by Google's Android Security Team.

Android is three billion devices of hardened, audited, relentlessly defended code, and fuzzing brings it down anyway. The method is brutally simple: Bury the system in malformed input, and wait for the rare case that cracks something open. Every crash is a lead, and behind it is usually a way in.

The Google engineers who authored this book do that for a living. They’ve fuzzed Android’s Binder IPC, the Pixel modem, the GPU drivers, and the kernel, uncovering root-level vulnerabilities the architecture was supposed to keep out of reach, and now they show you how they work.

Most fuzzing books stop at the concept; this one runs the campaign. You’ll learn how to:

Build reproducible fuzzing environments across emulators and physical devices
Target Android’s Binder IPC, native system services, GPU drivers, and kernel interfaces
Instrument code for coverage using AFL++ or libFuzzer and extend Syzkaller to reach new kernel drivers
Triage, reproduce, and investigate crashes to uncover real vulnerabilities
Develop the judgment to choose high- value targets and bypass runtime checks when appropriate.

Most modern and widely adopted languages, such as Rust, C, C++, C#, Java, jаvascript, Python, and Go, offer robust code coverage support, making them excellent candidates for coverage-guided fuzzing. If your target is written in a less common or domain-specific language, however, you might encounter difficulties implementing coverage-guided fuzzing. Furthermore, if you don’t have your target’s source code, you’ll likely need to rely on binary-only instrumentation to gain coverage support. While feasible, this approach generally demands a much higher level of effort to achieve correct functionality.

Who This Book Is For:
If you’re looking to fuzz programs on Android or on Linux, you’re looking to understand what fuzzing is, or you just want to dig deep into a major security practice used in software development today, then you’ll find this book relevant. To get the most use out of this book, you should know how to program in a major programming language.

Also, beware. If you love programming, fuzzing is one of those experiences that feels too rewarding when you first learn about it. Make sure to stop fuzzing periodically and make time for meals, sleep, your family, and other activities that together form a healthy life. We absolutely love fuzzing, not only because of the security vulnerabilities we find, but because it lets you take apart and inspect a program in a way that almost nothing else does. A well-written fuzzer is like having a friend looking over your shoulder, pointing out where your program became inconsistent so you can fix it. We hope that you’ll find this joy too.

Whether you’re a security researcher, an OEM security engineer, or a bug bounty hunter, Fuzzing Android is your operational playbook for finding vulnerabilities in the world’s largest mobile platform.

Covers: Android 17+ and is backward compatible with earlier AOSP releases.

Requires: A physical Android device or emulator (Cuttlefish); all required tools are open source.

Скачать Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel (Early Access)












[related-news] [/related-news]
Внимание
Уважаемый посетитель, Вы зашли на сайт как незарегистрированный пользователь.
Мы рекомендуем Вам зарегистрироваться либо войти на сайт под своим именем.