Resources
For a comprehensive library of research papers, click here.
Introductory articles
http://resources.infosecinstitute.com/intro-to-fuzzing/
http://www.brighthub.com/computing/smb-security/articles/9956.aspx
Blogs
http://gynvael.coldwind.pl/?id=524
http://www.squarefree.com/2007/08/02/introducing-jsfunfuzz/
http://ax330d.blogspot.com.au/
http://blog.mudynamics.com/category/fuzzing/
http://fuzztest.wordpress.com/
http://gdtr.wordpress.com/2012/05/11/fuzzing-hit-tracing/
Books
Fuzzing-focused
- Fuzzing: Brute force vulnerability discovery – Michael Sutton/Pedram Amini/Adam Greene [amazon]
- Fuzzing for software security testing and quality assurance – Ari Takanen/Jared DeMott/Charlie Miller [amazon]
- Open source fuzzing tools – Noam Rathaus/Gadi Evron [amazon]
Includes content on fuzzing
- Grey Hat Python – Justin Setiz [amazon]
- Mac Hackers Handbook – Charlie Miller/Dino Dai Zovi [amazon]
- iOS Hackers Handbook – Charlie Miller/Dino Dai Zovi/Dion Blazakis/Stefan Esser/Vincenzo Iozzo/Ralf-Philipp Weinmann [amazon]
Commercial Offerings
codenomicon – http://www.codenomicon.com/defensics/
Beyond Security BeStorm – http://www.beyondsecurity.com/black-box-testing.html
Spirent (previously MuSecurity) – http://www.spirent.com/Networks-and-Applications/App_Aware_Security