SDL Regex Fuzzer Overview

> [!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/56738f5e-cd8e-4669-8a19-fdf27734f585]

About This Video
SDL Regex Fuzzer is a tool to be used during the Verification phase of Microsoft Security Development Lifecycle (SDL). It can help test regular expressions for these potential vulnerabilities. Regular expression patterns containing certain clauses that execute in exponential time (for example, grouping clauses containing repetition that are themselves repeated) can be exploited by attackers to cause a denial-of-service (DoS) condition.

 

Published Date: 2/24/2011
Presented By: Bryan Sullivan and Georgeo Pulikkathara

Downloads

Video:WMV | MP4 | WMV (ZIP)