pkg.soopen package index

brew / Rang 13101

zzuf mit Homebrew, apt, dnf, MacPorts, Nix, pacman installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für zzuf in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install zzuf

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install zzuf

MacPorts ports tree · security/zzuf/Portfile · Quelle: api.github.com

Linux

Debian aptverifiziert · 92%
sudo apt install zzuf

Debian stable package indexes · zzuf · Quelle: deb.debian.org

Fedora dnfverifiziert · 92%
sudo dnf install zzuf

Fedora Rawhide package metadata · zzuf · Quelle: dl.fedoraproject.org

Nixverifiziert · 92%
nix profile install nixpkgs#zzuf

nixpkgs package indexes · pkgs/by-name/zz/zzuf/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S zzuf

Arch Linux sync databases · zzuf · Quelle: geo.mirror.pkgbuild.com

Überblick

Paketzusammenfassung

Transparent application input fuzzer

Befehle und Aliase

  • zzat
  • zzuf

Verlauf

Projektgeschichte und Nutzung

zzuf is Sam Hocevar's transparent application input fuzzer. It runs a target program while intercepting file and network operations, flips bits in input data deterministically, and reports crashes or other interesting behavior.

Projektgeschichte

zzuf grew out of the mid-2000s security and QA fuzzing culture around media parsers, image viewers, web browsers, and command-line utilities that consumed untrusted files. The Caca Labs page describes the project as a multi-purpose fuzzer whose goal is to make input fuzzing easier and more automated rather than inventing fuzzing itself.

The project had public talks and downloadable material by 2007 and 2008, including FOSDEM 2007 and Hacker Space Festival 2008 slides linked from the project page. The same page records early tarball attachments from 2008 and later snapshots, while the current development home is GitHub.

The manual-page source documents the mature command-line model: zzuf can run one program many times, vary seeds and fuzzing ratios, limit time, memory, bytes, and crashes, fuzz stdin when no command is given, and use preload or copy modes depending on platform support.

Adoptionsgeschichte

zzuf's own site names several adoption signals: Goatse Security used it against third-party applications, Adobe security researchers used it to stress-test applications and libraries, and CERT's Basic Fuzzing Framework was based on zzuf. The Fuzzing Project FAQ also lists zzuf as a simple, basic fuzzing tool for random input modification.

Its broader adoption is the classic small security-tool pattern: package managers keep a reproducible CLI available even after newer coverage-guided fuzzers became dominant, because zzuf is still useful for quick black-box corruption tests and deterministic reproducers.

Wie es verwendet wird

Typical usage is to prefix a command with zzuf, set a seed or seed range, and choose a corruption ratio. If a run crashes, the same seed can reproduce the mutated input; simple tools such as cat or cp can then materialize the exact fuzzed file for debugging or regression tests.

The manual also supports batch testing behavior: multiple jobs, maximum crash counts, wall-clock and CPU limits, output byte limits, memory limits, include/exclude filters, protected byte ranges, and network-fuzzing filters. That made zzuf useful both as a one-off terminal tool and as a scriptable QA/security harness.

Warum Paket-Nerds sich dafür interessieren

zzuf matters to package nerds because it is a compact Unix-style security tool with a long tail. It exposes a single memorable command, but underneath it depends on platform loader behavior, libc/file-operation interception, signal handling, and resource limits, which are exactly the details package maintainers have to preserve across operating systems.

It also captures a pre-AFL era of fuzzing in package form: deterministic random mutation, no source instrumentation, easy shell integration, and enough knobs to turn a simple idea into a practical crash-finding workflow.

Zeitleiste

  • 2007: The project page links FOSDEM 2007 zzuf presentation slides.
  • 2008: The project page links Hacker Space Festival 2008 slides and records early zzuf tarball attachments.
  • 2010: The Caca Labs attachment list records later zzuf and Mac OS X snapshot tarballs.
  • 2015-01-06: The bundled manual page source is dated 2015-01-06.
  • 2015-06-09: The Caca Labs zzuf page records its last modification by Sam Hocevar.

Related projects

  • Related projects and tools include CERT Basic Fuzzing Framework, american fuzzy lop, libFuzzer, honggfuzz, radamsa, Valgrind, AddressSanitizer, media players, image viewers, web browsers, objdump, and other parser-heavy targets for black-box fuzzing.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
zzatExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
zzufExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version0.15
Manager aktualisiert
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:zzuf
Version0.15
PaketmanagerHomebrew
Homepagehttp://caca.zoy.org/wiki/zzuf
Repositoryhttps://github.com/samhocevar/zzuf
Bottlenicht erfasst
Dienstkeiner deklariert

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Debian apt95%

zzuf 0.15-5+b1

transparent application fuzzer

https://caca.zoy.org/wiki/zzuf

sudo apt install zzuf
  • Section: devel
  • Architecture: amd64
  • Source Package: zzuf
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Zzuf
Debian stable package indexes · deb.debian.org · Debian stable package indexes: zzuf from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

zzuf

nix profile install nixpkgs#zzuf
  • normalized package name match
  • Abgeglichen nach: Zzuf
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/zz/zzuf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

zzuf 0.15-2build3

transparent application fuzzer

https://caca.zoy.org/wiki/zzuf

sudo apt install zzuf
  • Section: universe/devel
  • Architecture: amd64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Zzuf
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: zzuf from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
dnf95%

zzuf 0.15-27.fc45

Transparent application input fuzzer

http://sam.zoy.org/zzuf/

sudo dnf install zzuf
  • License: WTFPL
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: zzuf
  • 3 Abhängigkeiten
  • 2 stellt bereit
  • normalized package name match
  • Abgeglichen nach: Zzuf
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: zzuf from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst
pacman95%

zzuf 0.15-3

Transparent application input fuzzer

https://github.com/samhocevar/zzuf

sudo pacman -S zzuf
  • License: custom:WTF
  • Architecture: x86_64
  • 1 Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Zzuf
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: zzuf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

zzuf

sudo port install zzuf
  • normalized package name match
  • Abgeglichen nach: Zzuf
MacPorts ports tree · api.github.com · MacPorts ports tree: security/zzuf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation