As I’m currently developing the ‘next gen’ state-full fuzzing framework @ERNW [called dizzy, to be released soon š ], I will give you an updated set of fuzzing scripts from the ‘old world’.
Some of you will remember the 2008 release of sulley_l2, which was a modified version of the sulley fuzzing framework, enhanced with Layer 2 sending capabilities and a hole bunch of (L2) fuzzing scripts. All the blinking, rebooting, mem-corrupting ciscos gave us some attention. Back from then, we continued to write and use the fuzzing scripts, so the hole collection grew.
Find the latest version of the tool-set here.
If you take a look inside the ‘audits’ folder, you will find all the ERNW made fuzzing scripts. I’ll give you a short description on the most of them:
- ARP – This are some basic ARP fuzzing scripts, mainly as reference L2 implementation, haven’t found anything interesting with them, yet.
- BGP – Some scripts for the basic BGP packet types, has nothing to do with Layer2 but will kill some devices š
- CAPWAP – Within our wireless research we also did some wireless mgmt-protocol fuzzing and came up with this scripts. (RFC5415)
- CDP – Fuzzing scripts for Cisco’s discovery protocol. Most fun is gone here, as bugs were submitted and fixed by the time.
- DOT1Q – One of the first L2 fuzzing scripts, building a tagged packet.
- DTP – Fuzzing scripts for Cisco’s dynamic trunking protocol. Thats the one which make Ciscos blink like Christmas-Trees.
- EXTREME – A hand full of scripts targeting Extreme’sĀ discovery protocol, those will create purple stack traces š
- GTP – In the 3G / 4G research we did some GPRS tunneling protocol fuzzing, not finished yet.
- IP – Also more a reference implementation.
- ISL – As to be complete with the Vlan tagging there is also a script for Cisco’s ISL.
- LLDP – Those scripts won’t work as expected, if you know why, drop me a mail, you will get dizzy first š
- LWAPP – Also output from the wireless research, by that time this one randomly reboots access points.
- OSPF – A script for fuzzing OSPF HELO packets, wont get any further, as sulley knows no state.
- PNRP – Simon’s awesome PNRP fuzzing scripts.
- PVST – Spanning Tree in a few flavors, if you ever need even more of that packets š
- SNMP – Right, more like an ASN1 fuzzer, but provided some nice results.
- UDLD – One more L2 protocol with a bunch of strings inside (watch out for the device-id).
- VRRP – while implementing the VRRP attacks in loki, also did some fuzzing, obviously ;).
- VTP – An other L2 based, Cisco only protocol, make devices blinking.
- WLCCP – And the last one is again from our wireless research. Haven’t found anything interesting by fuzzing, but the loki module for this works nice.
So, thats all for now, have fun with the code and stay tuned for more tools on fuzzing to be finished/released soon.
enjoy
/daniel
Continue reading