Black Hat hackers face off in Iron Chef style competition

posted Jul 7th 2008 7:40pm by Juan Aguilar
filed under: cons, news


Which is a better method for finding vulnerabilities, fuzzing or static-code analysis? The question will be put to the test at next month’s Black Hat USA conference, where two experienced hackers security researchers will be given a piece of mystery code and one hour to find all the vulnerabilities they can using one of the two methods. [Charlie Miller] from Independent Security Evaluators will use fuzzing and [Sean Fay] from Fortify Software will use static-code analysis to detect the vulnerabilities in the code. We reported on [Miller]’s fuzzing talk while at Toorcon 9.

The pair will be allowed to use their own equipment, but they won’t see the code until the moment the showdown begins. For an added bit of fun, conference attendees are welcome to join in the contest. The audience member who finds the most exploits within the hour wins a free dinner at a new Las Vegas restaurant. But you don’t have to wait until then to weigh in; go ahead and post your thoughts on fuzzing vs. static-code analysis in the comments, just be ready to back up your claims.

Recent Posts



Reader Comments

Leave a Reply

hack a day serves up fresh hacks each day, every day from around the web and a special how-to hack each week.

send us your hacks





hacks

resources

rss newsfeeds

powered by wordpress

Most Commented On (30 days)

Recent Comments


  • Featured Mahalo How-Tos