Rode0Day
82 posts


Our next bug-finding rode0 will kick off in just under 30 minutes! To get started and prove how many bugs you can find, visit rode0day.mit.edu
English

@Toizi Things look okay on our end for that challenge- you appear to have found an unintented bug! Up to file 5.38, if you compile with -include stdio.h, your inputs cause a segfault!
The real version of file doesn't include stdio everywhere so it's not quite an N-day, but maybe close!
English

@NeolexSecurity Hey, we’re a bit overwhelmed with other projects at the moment so we probably won’t be running a competition this month but we should have something ready for next month which will launch on April 1!
English

@microsvuln Sorry for the downtime, we had some issues while moving our servers. A new competition will be starting in just a few days
English

@Rode0day And where are you guys at rode0day? no challenge anymore? can't wait for more challenges, I've armed myself with new fuzzers for hunting more! :-)
English
Rode0Day retweetou

We (@moyix, @DynaWhat, and Tim Leek) wrote an article for @securityprivacy on "The @Rode0day to Less-Buggy Programs." Check it out here - ieeexplore.ieee.org/document/88869…
English
Rode0Day retweetou

Brendan @moyix just talked about Rode0day #fuzzing competition @shonanmtg. The challenge set includes many interesting targets and i think it could be a good benchmark for fuzzing evaluation.

English

@andreafioraldi @andrewfasano If you tested it manually with the right args, then it’s probably not a bug in simple CRS or your fork. Let me know how your testing goes!
English

@andrewfasano @Rode0day I'm not at home atm, later i will also try to send the crash using original simple-crs and I will also debug a bit to see if it is a lava bug. Unfortunately, if it isn't a lava bug the testcase may not trigger the same buggy code in the original binary.
English

I've just started @Rode0day to test AFL++ CompareCoverage + MOpt (rode0day.mit.edu/profile/malwei…).
I spotted a bug in my NeverZero implementation in AFL++ while doing the setup :)
Only 2 of the 4 binaries can run in QEMU out-of-the-box.
Does anyone else want to compete? I feel alone.
English

Our latest bug-finding rode0 has begun! Good luck bug-finders rode0day.mit.edu/results
English
Rode0Day retweetou

It's been one year since we launched our continuous bug-finding competition, @Rode0day! We've spent the past year learning all we can about bugs and bug-finding and tomorrow morning, I'll be presenting some of what we've found at #woot19 usenix.org/conference/woo…
English

There are still many undiscovered bugs in this month's bug-finding rodeo so we've pushed back the end date. Good luck bug-finders!
Rode0Day@Rode0day
Our July Rode0day featuring buggy versions of sqlite, libjpeg, file, jq, and tinyexpr has begun! Our bugs this month are a bit different from usual. Think you can find them? Join the competition at rode0day.mit.edu
English

Our July Rode0day featuring buggy versions of sqlite, libjpeg, file, jq, and tinyexpr has begun! Our bugs this month are a bit different from usual. Think you can find them? Join the competition at rode0day.mit.edu
English

@MurmusCTF It will probably start next Wednesday and run for 2 weeks so we can get back on our regular schedule.
English

Interested in joining our next bug-finding rodeo but don't know where to start? Check out this excellent video series from @MurmusCTF showing how to compete using AFL! youtube.com/watch?v=-uCnP6…

YouTube
English

And @MurmusCTF is now running a competition to triage some of his libjpeg crashes and write exploits for them. We're pretty sure many of these bugs are exploitable, so give it a try- github.com/murmus/Rode0Tr…. There are even prizes!
English

