Cristian Cadar · FUZZING'23 · 2023 · International Fuzzing Workshop

Watch the talk

What it does with SQLancer

A fuzzing keynote that reaches for SQLancer as its example of a fuzzer that found hundreds of bugs in mature database systems, and later reads out SQLite's own line about the project's author, agreeing with it.

cites as examplerecognition

Where SQLancer comes up (4)

  • 4:55
    as another example SQL lenser which is a fer for database Management Systems again it has found hundreds of bugs in popular database Management Systems like sqlite and postgress SQL
    From the talk's automatic captions — a machine transcription of speech, not the speaker's words as written: it renders the name as “SQL lenser”. Follow the link to hear what was said.
  • 4:55
    A slide of fuzzers that made a difference — KLEE, SAGE, AFL, OSS-Fuzz, Csmith and EMI — ending with SQLancer as the DBMS fuzzer, with the bug count it found in popular database systems.
    The talk at 4:55. A slide of fuzzers that made a difference — KLEE, SAGE, AFL, OSS-Fuzz, Csmith and EMI — ending with SQLancer as the DBMS fuzzer, with the bug count it found in popular database systems.
    A frame from the recording. Nothing is transcribed from it: what the slide says is shown, not quoted.
  • 25:09
    so I have this quote here and I think that you know if Manuel would be here he would certainly blush uh it says one fing researcher of particular noce Manuel riger and I completely agree with that this is actually from the sqlite web page
    From the talk's automatic captions — a machine transcription of speech, not the speaker's words as written. Follow the link to hear what was said.
  • 25:09
    The slide displays SQLite's own paragraph about the project's author, attributed on the slide to the SQLite webpage. Its wording is in the dataset already, quoted from sqlite.org/testing.html.
    The talk at 25:09. The slide displays SQLite's own paragraph about the project's author, attributed on the slide to the SQLite webpage. Its wording is in the dataset already, quoted from sqlite.org/testing.html.
    A frame from the recording. Nothing is transcribed from it: what the slide says is shown, not quoted.

What was read

  • captions — extracted, 456 caption segments
    Windows around candidate moments, read out of YouTube's transcript panel in a browser. Not the whole talk: only the segments a loose prefilter flagged, so the matcher decides on text a person can check.
  • frame — extracted
    Captured at 4:55.
  • frame — extracted
    Captured at 25:09.

This record is talks.json, under the id talk:youtube:6YGqFRTe2D0.