BED
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
BED (Bruteforce Exploit Detector) is a protocol fuzzer that checks daemons for potential buffer overflows, format string bugs, and other vulnerabilities by sending crafted protocol-specific data.
BASIC USAGE#
bed -s <plugin> -t <target> # Fuzz target with specified plugin
OPTIONS#
bed -s <plugin> # Select protocol plugin bed -t <target> # Target IP address bed -p <port> # Target port bed -o <timeout> # Timeout in seconds (default: 2)
PROTOCOL PLUGINS (-s)#
bed -s FTP -t <target> # Fuzz FTP server bed -s SMTP -t <target> # Fuzz SMTP server bed -s POP -t <target> # Fuzz POP3 server bed -s HTTP -t <target> # Fuzz HTTP server bed -s IRC -t <target> # Fuzz IRC server bed -s IMAP -t <target> # Fuzz IMAP server bed -s PJL -t <target> # Fuzz PJL (Printer Job Language) bed -s LPD -t <target> # Fuzz LPD (Line Printer Daemon) bed -s FINGER -t <target> # Fuzz Finger service bed -s SOCKS4 -t <target> # Fuzz SOCKS4 proxy bed -s SOCKS5 -t <target> # Fuzz SOCKS5 proxy
EXAMPLES#
# Fuzz FTP server on default port bed -s FTP -t 192.168.1.1 # Fuzz SMTP server on custom port bed -s SMTP -t 192.168.1.1 -p 2525 # Fuzz HTTP server with longer timeout bed -s HTTP -t 192.168.1.1 -o 5 # Fuzz POP3 server bed -s POP -t 192.168.1.1 -p 110 # Fuzz IRC server bed -s IRC -t 192.168.1.1 -p 6667
WHAT BED TESTS#
# For each protocol, BED sends: # - Oversized strings (buffer overflow) # - Format string characters (%s, %n, %x) # - Special characters (null bytes, newlines) # - Long repeated patterns # - Protocol-specific malformed commands # - Boundary value inputs
INTERPRETING RESULTS#
# If the target crashes or becomes unresponsive: # - Note the exact test case that caused the crash # - Record the payload size and content # - This indicates a potential vulnerability # If no crash occurs: # - The service handled malformed input properly # - Does NOT guarantee absence of vulnerabilities
WORKFLOW#
# 1. Identify target service and port # 2. Select appropriate BED plugin # 3. Run BED against the target # 4. Monitor target for crashes # 5. Note which test cases cause issues # 6. Investigate crashes with debugger (GDB/OllyDbg) # 7. Develop proof-of-concept exploit
NOTES#
- Perl-based tool - Can crash target services (use in lab environments) - Test one service at a time - Monitor target with debugger for crash analysis - Does not exploit vulnerabilities, only finds them - Useful first step before manual fuzzing - Legacy tool - consider boofuzz/AFL for modern fuzzing