Nullcon Goa 2025: What The PHUZZ?! Finding 0-Days In PHP Apps wt Coverage-guided Fuzzing - Sebastian
About this talk
This talk presents PHUZZ, an open-source prototype that integrates coverage-guided fuzz testing specifically designed for PHP web applications. The speaker discusses how PHUZZ surpasses popular web vulnerability scanners, such as BurpSuite Pro, ZAP, and WFuzz, in identifying a variety of server-side and client-side vulnerabilities, including SQL injection, remote code execution, XML external entity attacks, and cross-site scripting in both artificial and real-world contexts. Additionally, the session covers the challenges of applying coverage-guided fuzzing to web applications, highlighting PHUZZ's function hooking and vulnerability detection techniques that led to the identification of over 20 potential security issues and 2 CVEs in widely used WordPress plugins.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
26:30
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01