Cornelius Aschermann
banner
is-eqv.bsky.social
Cornelius Aschermann
@is-eqv.bsky.social
Fuzzing & stuff https://hexgolems.com
But only if we like the domain of your email address.
October 26, 2025 at 4:29 PM
Reposted by Cornelius Aschermann
cut my heap into pieces, this is my crash report:
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()
May 31, 2025 at 5:26 PM
I love this. I've been using dwarf data for a while now (I think the design space of "you have source, but you'd rather do binary analysis with dwarf on debug builds"-tools is kinda under explored). But I never treated dwarf as a database format to safe results in.
May 27, 2025 at 11:40 PM
Seems like Atropos does most of that too - i.e. automatically inferring some kind of "spec" in a way - it just doesn't use OpenAPI, I think? (except for also having coverage feedback & snapshot).
April 18, 2025 at 4:30 AM
What's the delta between this and Atropos? Not limited to PHP?
April 18, 2025 at 1:28 AM
Have been making the exact same experience - tried very hard to use perplexity pro for a couple of days, hardly ever found a problem easy enough for the AI to solve, with some outlandishly easy things failing even on claude etc.
March 24, 2025 at 10:29 PM
Now, if someone combines this paper with www.usenix.org/conference/u... (which already some similar stuff) I would totally expect that fuzzing outperforms static analysis on web-app security issues just as harshly as we know it to outperform static analysis on the native side.
Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities | USENIXusenix_logo_notag_white
www.usenix.org
March 4, 2025 at 5:09 AM
Next thing: a bunch of 'em go all "shocked pikatchu"over the realisation that there's a ton of ADHD and/or Autistic folks in CS 🤣
February 26, 2025 at 5:24 AM
And those that aren't, are usually friends with quite a few of those that are ...
February 26, 2025 at 4:14 AM
Check out ghostcell: plv.mpi-sws.org/rustbelt/gho... with the presentation: www.youtube.com/watch?v=jIbu... for a way to make 0 overhead, proven safe, cyclic datastructures with actual references in rust.
plv.mpi-sws.org
February 22, 2025 at 8:08 PM
arxiv.org/abs/2502.12115 can't argue with the science on that one: LLM's are solving almost 60% of the manager tasks, but only 40% of SWE tasks :P
SWE-Lancer: Can Frontier LLMs Earn $1 Million from Real-World Freelance Software Engineering?
We introduce SWE-Lancer, a benchmark of over 1,400 freelance software engineering tasks from Upwork, valued at \$1 million USD total in real-world payouts. SWE-Lancer encompasses both independent engi...
arxiv.org
February 21, 2025 at 6:49 PM