← All cheat sheets

BED

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

BED (Bruteforce Exploit Detector) is a protocol fuzzer that checks
daemons for potential buffer overflows, format string bugs, and
other vulnerabilities by sending crafted protocol-specific data.

BASIC USAGE#

bed -s <plugin> -t <target>      # Fuzz target with specified plugin

OPTIONS#

bed -s <plugin>                  # Select protocol plugin
bed -t <target>                  # Target IP address
bed -p <port>                    # Target port
bed -o <timeout>                 # Timeout in seconds (default: 2)

PROTOCOL PLUGINS (-s)#

bed -s FTP -t <target>           # Fuzz FTP server
bed -s SMTP -t <target>          # Fuzz SMTP server
bed -s POP -t <target>           # Fuzz POP3 server
bed -s HTTP -t <target>          # Fuzz HTTP server
bed -s IRC -t <target>           # Fuzz IRC server
bed -s IMAP -t <target>          # Fuzz IMAP server
bed -s PJL -t <target>           # Fuzz PJL (Printer Job Language)
bed -s LPD -t <target>           # Fuzz LPD (Line Printer Daemon)
bed -s FINGER -t <target>        # Fuzz Finger service
bed -s SOCKS4 -t <target>       # Fuzz SOCKS4 proxy
bed -s SOCKS5 -t <target>       # Fuzz SOCKS5 proxy

EXAMPLES#

# Fuzz FTP server on default port
bed -s FTP -t 192.168.1.1

# Fuzz SMTP server on custom port
bed -s SMTP -t 192.168.1.1 -p 2525

# Fuzz HTTP server with longer timeout
bed -s HTTP -t 192.168.1.1 -o 5

# Fuzz POP3 server
bed -s POP -t 192.168.1.1 -p 110

# Fuzz IRC server
bed -s IRC -t 192.168.1.1 -p 6667

WHAT BED TESTS#

# For each protocol, BED sends:
# - Oversized strings (buffer overflow)
# - Format string characters (%s, %n, %x)
# - Special characters (null bytes, newlines)
# - Long repeated patterns
# - Protocol-specific malformed commands
# - Boundary value inputs

INTERPRETING RESULTS#

# If the target crashes or becomes unresponsive:
# - Note the exact test case that caused the crash
# - Record the payload size and content
# - This indicates a potential vulnerability

# If no crash occurs:
# - The service handled malformed input properly
# - Does NOT guarantee absence of vulnerabilities

WORKFLOW#

# 1. Identify target service and port
# 2. Select appropriate BED plugin
# 3. Run BED against the target
# 4. Monitor target for crashes
# 5. Note which test cases cause issues
# 6. Investigate crashes with debugger (GDB/OllyDbg)
# 7. Develop proof-of-concept exploit

NOTES#

- Perl-based tool
- Can crash target services (use in lab environments)
- Test one service at a time
- Monitor target with debugger for crash analysis
- Does not exploit vulnerabilities, only finds them
- Useful first step before manual fuzzing
- Legacy tool - consider boofuzz/AFL for modern fuzzing