Re: EAP fuzzer
From: Alan DeKok (alanddeployingradius.com)
Date: Sun, 16 Sep 2007 00:07:59 -0700 (PDT)
Bernard Aboba wrote:
> I'm not aware of any publicly available EAP fuzzing tools.  However,
> based on my experience testing EAP peer, server and authenticator
> implementations, it is quite likely that such a tool would turn up some
> significant bugs, potentially even ones that would enable development of
> "EAP malware".

  There is already software that exploits publicly disclosed issues in
EAP implementations.

  And while implementing EAP methods for FreeRADIUS, I've seen client
crashes when the server didn't quite behave as expected.

  Alan DeKok.
  • EAP fuzzer Axel Rengstorf, September 14 2007
    • Re: EAP fuzzer Bernard Aboba, September 15 2007
      • Re: EAP fuzzer Alan DeKok, September 16 2007

Results generated by Tiger Technologies using MHonArc.