Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/184031
Title: Solving real world security problems: hacking and protection
Authors: Tham, Holdon
Keywords: Computer and Information Science
Issue Date: 2025
Publisher: Nanyang Technological University
Source: Tham, H. (2025). Solving real world security problems: hacking and protection. Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/184031
Project: CCDS24-0436
Abstract: Fuzzing of Commercial Off-The-Shelf router firmwares is a critical task to find vulnerabilities, allowing developers to fix them before threat actors are able to exploit and compromise the confidentiality, integrity and availability of user’s data and Internet traffic. However, current fuzzing software do not take into account the HyperText Transfer Protocol (HTTP) requirements needed for a successful request to a router’s web server. On top of that, the fuzzing experiments require the user to manually collect seeds or use generic ones, reducing its ability to explore deeper into the firmware’s logic. To address this, this report proposes the use of a HTTP custom mutator as well as a seed scraper, which automatically collects up to 5 POST requests obtained from the web server. The combination of the custom mutator and custom seed, as well as the standard American Fuzzy Lop ++ (AFL++) fuzzer and generic seeds resulted in an increase in map size as well as saved crashes and hangs, while fuzzing cycles remain low. This indicates higher code coverage and the discovery of more interesting test cases which may be missed by the standard mutator and generic seeds.
URI: https://hdl.handle.net/10356/184031
Schools: College of Computing and Data Science 
Fulltext Permission: restricted
Fulltext Availability: With Fulltext
Appears in Collections:CCDS Student Reports (FYP/IA/PA/PI)

Files in This Item:
File Description SizeFormat 
Tham_Holdon_NTU-FYP Report.pdf
  Restricted Access
1.17 MBAdobe PDFView/Open

Page view(s)

18
Updated on May 7, 2025

Download(s)

4
Updated on May 7, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.