Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
litefuzz — A multi-platform fuzzer for poking at userland binaries, network clients and servers | Kitploit
Tools/GitHubGitHub/sec-tools/litefuzz
Vulnerability AnalysisExploitationFuzzingPenetration TestingBinary Analysis
GitHubsec-tools/litefuzz

litefuzz

A multi-platform fuzzer for poking at userland binaries, network clients and servers

View Repository
6910289 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

litefuzz

A multi-platform fuzzer for poking at userland binaries, clients and servers.

It has found bugs in 50+ apps and libraries from top companies and open soruce.

Simple setup to start fuzzing on Linux, Mac and Windows.

  • litefuzz
    • intro
    • why
    • how it works
      • what it does
      • what it doesn't do
    • support
      • python versions
      • linux
      • mac
      • windows
      • targets
      • triage
    • getting started
      • tests
        • unit tests
        • crashing app tests
    • options
      • crash directory
      • insulate mode
      • timeout
      • mutators
      • ReportCrash
      • pause
      • reusing crashes for variant finding
      • memory debugging helpers
      • checking live target output
      • client and server modes
      • local network examples
      • remote network examples
        • client
        • server
          • TLS
        • multiple data exchange modes
      • attaching to a process
      • crash artifacts
      • golang
      • repros
      • remove file
      • minimization
      • command
    • examples
      • local app
        • quick look
        • enumerating file handlers on Ubuntu
        • enumerating file handlers on OS X
      • client
        • quick look
        • local client
        • remote client
      • server
        • quick look
        • local server
        • remote server
  • command line
  • trophies
  • FAQ
    • how did this project come about?
    • is this project actively maintained?
    • how do you know the fuzzer is working well and did you measure it against others?
    • what would you change if you were to re-write it today?
    • how stable is litefuzz?
    • are there unsupported scenarios for litefuzz?
    • what guarentees are given for this project or it's code?
    • author / references

intro

Litefuzz is meant to serve a purpose: fuzz and triage on all the major platforms, support both CLI/GUI apps, network clients and servers in order to find security-related bugs.

It simplifies the process and makes it easy to discover security bugs in many different targets, across platforms, while just making a few honest trade-offs.

It isn't built for speed, scalability or meant to win any prizes in academia. It applies simple techniques at various angles to yield results. For console-based file fuzzing, you should probably just use AFL. It has superior performance, instrumention capabilities (and faster non-instrumented execs), scale and can make freakin' jpegs out of thin air. For networking fuzzing, the mutiny fuzzer also works well if you have PCAPs to replay and frizzer looks promising as well. But if you want to give this one a try, it can fuzz those kinds of targets across platforms with just a single tool.

./ and give your target... a lite fuzz.

$ sudo apt install -y latex2rtf

$ ./litefuzz.py -l -c "latex2rtf FUZZ" -i input/tex -o crashes/latex2rtf -n 1000 -z
--========================--
--======| litefuzz |======--
--========================--

[STATS]
run id:     3516
cmdline:    latex2rtf FUZZ
crash dir:  crashes/latex2rtf
input dir:  input/tex
inputs:     1
iterations: 1000
mutator:    random(mutators)

@ 1000/1000 (3 crashes, 127 duplicates, ~0:00:00 remaining)

[RESULTS]
> completed (1000) iterations with (3) unique crashes and 127 dups
>> check crashes/latex2rtf for more details

This is a simple local target which AFL++ is perfectly capable of handling and just quickly given as an example. Litefuzz was designed to do much more in the way of network and GUI fuzzing which you'll see once you dive in.

why

Yes, another fuzzer and one that doesn't track all that well with the current trends and conventions. Trade-offs were made to address certain requirements. These requirements being a fuzzer that works by default on multiple platforms, fuzzes both local and network targets and is very easy to use. Not trying to convince anybody of anything, but let's provide some context. Some targets require a lot of effort to integrate fuzzers such as AFL into the build chain. This is not a problem as this fuzzer does not require instrumentation, sacraficing the precise coverage gained by instrumentation for ease and portability. AFL also doesn't support network fuzzing out of the box, and while there are projects based on it that do, they are far from straightforward to use and usually require more code modifications and harnesses to work (similar story with Libfuzzer).

It doesn't do parallel fuzzing, nor support anything like the blazing speed improvments that persistent mode can provide, so it cannot scale anywhere close to what fuzzers with such capabilities. Again, this is not a state-of-the-art fuzzer. But it doesn't require source code, properly up a build or certain OS features. It can even fuzz some network client GUIs and interactive apps. It lives off the land in a lot of ways and many of the features such as mutators and minimization were just written from scratch.

It was designed to "just work" and effort has been put into automating the setup and installation for the few dependencies it needs. This fuzzer was written to serve a purpose, to provide value in a lot of different target scenarios and environments and most importantly and for what all fuzzers should ultimately be judged on: the ability to find bugs. And it does find bugs. It doesn't presume there is target source code, so it can cover closed source software fairly well. It can run as part of automation with little modification, but is geared towards being fun to use for vulnerability researchers. It is however more helpful to think of it as a R&D project rather than a fully-fledged product. Also, there's no complicated setup where it's slightly broken out of the box or needs more work to get it running on modern operating systems.

It's been tested working on Ubuntu Linux, Mac and Windows and comes with fully functional scripts that do just about everything for you in order to setup a ready-to-fuzz environment.

Once the setup script completes, it only takes a few minutes to get started fuzzing a ton of different targets.

how it works

Litefuzz supports three different modes: local, client and server.

Download Tool