Sunday, June 28, 2009

IOCTL Fuzzer v1.1 Released

IOCTL Fuzzer is a tool designed to automate the task of searching vulnerabilities in Windows kernel drivers by performing fuzz tests on them.

The fuzzer’s own driver hooks NtDeviceIoControlFile in order to take control of all IRPs throughout the system.

While processing IRPs, the fuzzer will spoof those IRPs conforming to conditions specified in the configuration file. A spoofed IRP is identical to the original IRP in all respects except the input data, which is changed to randomly generated fuzz.

IOCTL Fuzzer works on Windows XP, 2003 Server, Vista and 2008 Server.

Usage: ioctl_fuzzer.exe [config.xml]
If no configuration file is specified, the tool will start in monitoring mode.

Program capabilities:
* IRP filtering by process name, driver name, device name, or I/O Control code
* IRP fuzzing
* monitoring mode
* logging output to console and/or file.

While processing IRPs, the fuzzer will spoof those IRPs conforming to conditions specified in the configuration file. A spoofed IRP is identical to the original IRP in all respects except the input data, which is changed to randomly generated fuzz.

Download

Source

No comments: