{"product_id":"fuzzing-android-finding-vulnerabilities-in-userspace-and-the-kernel","title":"Fuzzing Android: Finding Vulnerabilities in Userspace and the Kernel","description":"\u003cb\u003eThe operational playbook for fuzzing Android, from Binder services to the Linux kernel, by Google's Android Security Team.\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eAndroid is three billion devices of hardened, audited, relentlessly defended code, and fuzzing brings it down anyway. The method is brutally simple: Bury the system in malformed input, and wait for the rare case that cracks something open. Every crash is a lead, and behind it is usually a way in.\u003cbr\u003e\u003cbr\u003eThe Google engineers who authored this book do that for a living. They\u0026amp;rsquo;ve fuzzed Android\u0026amp;rsquo;s Binder IPC, the Pixel modem, the GPU drivers, and the kernel, uncovering root-level vulnerabilities the architecture was supposed to keep out of reach, and now they show you how they work.\u003cbr\u003e\u003cbr\u003eMost fuzzing books stop at the concept; this one runs the campaign. You\u0026amp;rsquo;ll learn how to:\u003cbr\u003e\u003cul\u003e\n\u003cli\u003eBuild reproducible fuzzing environments across emulators and physical devices\u003c\/li\u003e\n\u003cli\u003eTarget Android\u0026amp;rsquo;s Binder IPC, native system services, GPU drivers, and kernel interfaces\u003c\/li\u003e\n\u003cli\u003eInstrument code for coverage using AFL++ or libFuzzer and extend Syzkaller to reach new kernel drivers\u003c\/li\u003e\n\u003cli\u003eTriage, reproduce, and investigate crashes to uncover real vulnerabilities\u003c\/li\u003e\n\u003cli\u003eDevelop the judgment to choose high- value targets and bypass runtime checks when appropriate.\u003c\/li\u003e\n\u003c\/ul\u003e\u003cbr\u003eWhether you\u0026amp;rsquo;re a security researcher, an OEM security engineer, or a bug bounty hunter, \u003ci\u003eFuzzing Android\u003c\/i\u003e is your operational playbook for finding vulnerabilities in the world\u0026amp;rsquo;s largest mobile platform.\u003cbr\u003e\u003cbr\u003eCovers: Android 17+ and is backward compatible with earlier AOSP releases. \u003cbr\u003e\u003cbr\u003eRequires: A physical Android device or emulator (Cuttlefish); all required tools are open source.","brand":"No Starch Press","offers":[{"title":"US - Paperback","offer_id":49729932624099,"sku":"DTRPRUS-9781718505292","price":459.0,"currency_code":"HKD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1778\/4925\/files\/9781718505292.jpg?v=1789342296","url":"https:\/\/buybookbook.com\/en-mo\/products\/fuzzing-android-finding-vulnerabilities-in-userspace-and-the-kernel","provider":"買書書 BuyBookBook","version":"1.0","type":"link"}