Overview
What this challenge is about.
Fuzz a memory-unsafe image parser for HealthTech, triage ASan bugs, ship fix PRs, and earn a verifiable certificate.
The scenario
The health-imaging vendor (FDA-cleared Class II software, HIPAA-regulated) is preparing for a hospital-system penetration test in 8 weeks — leadership wants known classes of memory-safety bugs eliminated before the test.
The Brief
What you'll do, and what you'll demonstrate.
Set up coverage-guided fuzzing on 3 image-parsing entry points, find and fix the top 5 memory-safety bugs, and leave fuzzing running in CI.
Earning criteria — what you'll demonstrate
- Build coverage-guided fuzzing harnesses for real C++ entry points
- Use ASan + UBSan to triage memory-safety findings
- Ship fixes with regression tests that prevent re-introduction
- Operationalize fuzzing in CI with corpus + budget guidance
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Fuzzing
Apply fuzzing to solve real industry problems and demonstrate production-level capability.
- Memory Safety
Apply memory safety to solve real industry problems and demonstrate production-level capability.
- Address Sanitizer
Apply address sanitizer to solve real industry problems and demonstrate production-level capability.
- Secure Coding
Apply secure coding to solve real industry problems and demonstrate production-level capability.
- Vulnerability Triage
Apply vulnerability triage to solve real industry problems and demonstrate production-level capability.
- Ci Cd
Apply ci cd to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles: