September 26, 2026
During the first semester of my sophomore year of college studying at BITS Pilani (~Dec 2025, during our final exams), I got a mail in my inbox (not personal, it was sent to everyone) from the Dean of BITS Pilani on behalf of the Penetration Testing Centre, BITS-WILP offering students the chance to join a team that was being built for the Cybersecurity Innovation Challenge held by the Ministry of Electronics and Information Technology of India.
Out of the 10 problems that were posted on the website, one in particular caught my eye: “Security in distributed wireless networks”. While most of the others were fields that I could not make an impact in with my current experience (for instance, expecting college students to design post-quantum secure messaging - problem 5 - is quite surprising), this project seemed within reach of my skills back then. Granted, one could say that I was being a bit ambitious here: I did not possess much programming skills (barring my knowledge of C), nor did I have practical cybersecurity skills (although my travels in cybersecurity rooms across cyberspace did provide me with a good framework). I still moved on with the project, shot a mail and began to work.
At the end of the project came Fuzzie - a design which had some interesting ideas, but at the end of the day did not come to fruition (as far as I know, WILP has picked up the pieces of the project and have been working on their own version, but that version is not related to me nor have I worked on it). The design, while it did make it to the second stage of the competition, was not particularly sound. What actually hurt the project the most was that the concepts involved were not well-defined enough to actually be able to program it. This was mostly my fault - the design was mine, and I was trying to learn fuzzing concepts and vulnerability analysis in a span of around a month. Needless to say, it did not make sense as a design.
There was a chance for redemption, which was that after getting selected for the third round, we would have a month to create a prototype. However, due to some reasons (which I am not particularly aware of), our time got cut to three days. This meant that I lost my chance to fix the design. We submitted something at the end, but not the best work possible.
I do still wish to work on fuzzing, and perhaps even find a vulnerability at some point - and hence this new series.
Further details will be posted in the coming weeks - the initial one being a writeup on why and how researchers fuzz software.