{"id":13936320,"url":"https://github.com/IOActive/XDiFF","last_synced_at":"2025-07-19T21:32:22.429Z","repository":{"id":148216731,"uuid":"109631224","full_name":"IOActive/XDiFF","owner":"IOActive","description":"Extended Differential Fuzzing Framework","archived":false,"fork":false,"pushed_at":"2018-04-13T06:38:59.000Z","size":389,"stargazers_count":320,"open_issues_count":0,"forks_count":56,"subscribers_count":22,"default_branch":"master","last_synced_at":"2024-11-27T04:30:54.041Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/IOActive.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-11-06T01:10:00.000Z","updated_at":"2024-08-12T19:33:51.000Z","dependencies_parsed_at":null,"dependency_job_id":"fbeaab34-3f47-4c70-a657-b7dbbd0d3fba","html_url":"https://github.com/IOActive/XDiFF","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/IOActive/XDiFF","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/IOActive%2FXDiFF","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/IOActive%2FXDiFF/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/IOActive%2FXDiFF/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/IOActive%2FXDiFF/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/IOActive","download_url":"https://codeload.github.com/IOActive/XDiFF/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/IOActive%2FXDiFF/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":266019657,"owners_count":23864916,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-07T23:02:33.967Z","updated_at":"2025-07-19T21:32:17.410Z","avatar_url":"https://github.com/IOActive.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# What is XDiFF?\n XDiFF is an Extended Differential Fuzzing Framework built for finding \n vulnerabilities in software. It collects as much data as possible from \n different executions an then tries to infer different potential vulnerabilities \n based on the different outputs obtained.\n The vulnerabilities can either be found in isolated pieces of software or by \n comparing:\n  * Different inputs\n  * Different versions\n  * Different implementations\n  * Different operating systems' implementations\n\n The fuzzer uses Python and runs on multiple OSs (Linux, Windows, OS X, and \n Freebsd). Its main goal is to detect issues based on diffential fuzzing aided \n with the extended capabilities to increase coverage. Still, it will found\n common vulnerabilities based on hangs and crashes, allowing to attach a \n memory debugger to the fuzzing sessions.\n\n## Quick guide\nPlease follow the following steps:\n1. [Install](https://github.com/IOActive/XDiFF/wiki/1.-Install) XDiFF\n2. Define [the input](https://github.com/IOActive/XDiFF/wiki/2.-The-input)\n3. Define [the software](https://github.com/IOActive/XDiFF/wiki/3.-The-software)\n4. Run [the fuzzer](https://github.com/IOActive/XDiFF/wiki/4.-The-fuzzer)\n5. Analyze [the output](https://github.com/IOActive/XDiFF/wiki/5.-The-output) \n6. ...\n7. Profit!\n\n## Disclaimer\nThe tool and the fuzzing process can be susceptible to code execution. \nUse it at your own risk always inside a VM. \n\n## Authors\n- Fernando Arnaboldi - _Initial work_\n- [cclauss](https://github.com/cclauss)\n\nFor contributions, please propose a [Changelog](https://github.com/IOActive/XDiFF/wiki/Changelog) entry in the pull-request comments.\n\n## Acknowledgments\nThanks Lucas Apa, Tao Sauvage, Scott Headington, Carlos Hollman, Cesar Cerrudo, Federico Muttis, Topo for their feedback and Arlekin for the logo.\n\n## License\nThis project is licensed under the GNU general public license version 3.\n\n## Logo\n![XDiFF Logo](https://user-images.githubusercontent.com/12038478/33187082-ec625f3e-d06d-11e7-831a-08e11823a391.png)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FIOActive%2FXDiFF","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FIOActive%2FXDiFF","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FIOActive%2FXDiFF/lists"}