diff options
Diffstat (limited to 'fuzz/fuzz_tls.cpp')
| -rw-r--r-- | fuzz/fuzz_tls.cpp | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/fuzz/fuzz_tls.cpp b/fuzz/fuzz_tls.cpp new file mode 100644 index 0000000..7860426 --- /dev/null +++ b/fuzz/fuzz_tls.cpp @@ -0,0 +1,17 @@ +#include <cstddef> +#include <cstdint> + +#include "wireframe/l7/tls.hpp" + +// The nested TLV walk (record -> handshake -> extensions -> SNI, each +// level bounds-checked against attacker-influenced length fields) is +// the most structurally complex hand-rolled parser in the project so +// far - exactly the kind of code most likely to have an off-by-one or +// an unchecked length feeding a read past the buffer. +extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { + wireframe::net::parse_tls_client_hello({data, size}); + + wireframe::net::TlsSniDissector dissector; + dissector.summarize({data, size}); + return 0; +} |