Penetration testing

Binary Exploitation & Fuzzing

Compiled software, firmware and embedded devices are where the deep bugs live and where scanners give up. We fuzz and reverse them by hand - the work that took a Mitel IP phone from nothing to unauthenticated root (CVE-2024-31963).

Book a scoping call

Binaries, parsers, protocols, firmware

  • File parsers and format handlers
  • Network protocol implementations
  • Native libraries and system services
  • Embedded and IoT firmware, from extraction to exploitation

Coverage-guided fuzzing, then a human

We build custom harnesses so the fuzzer reaches the interesting code, run coverage-guided campaigns with sanitizers (ASan, MSan, UBSan), and then do the part tools cannot: triage each crash, find the root cause, and judge whether it is actually exploitable. Reverse engineering fills in what no source explains - the hidden debug flag, the undocumented parameter, the assumption the developer made.

Crashes triaged, impact judged

  • Each crash with a stack trace, root-cause analysis and a reproducing test case
  • An exploitability rating, and a proof-of-concept where one is warranted
  • A management summary and a technical report with a clear order to fix in
  • A walkthrough with a Q&A round, and a retest once you have remediated

Related reading: exploiting an embedded Mitel phone to unauthenticated RCE and turning a finding into a Metasploit module.

Have us break the binary

A 30-minute call is enough to scope a fuzzing or reversing engagement.

Book a scoping call