blob: 7860426635f4a2b1f9ec078edd6991f16c476fba (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
#include <cstddef>
#include <cstdint>
#include "wireframe/l7/tls.hpp"
// The nested TLV walk (record -> handshake -> extensions -> SNI, each
// level bounds-checked against attacker-influenced length fields) is
// the most structurally complex hand-rolled parser in the project so
// far - exactly the kind of code most likely to have an off-by-one or
// an unchecked length feeding a read past the buffer.
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
wireframe::net::parse_tls_client_hello({data, size});
wireframe::net::TlsSniDissector dissector;
dissector.summarize({data, size});
return 0;
}
|