6 ms·
The maintainer it's active still with a bugs mailing list and chat in IRC. Your findings would surely be well received.
by jamestomasino 7y ago
The maintainer it's active still with a bugs mailing list and chat in IRC. Your findings would surely be well received.
- tptacek 7y agoMy "findings" here would just be "take the first recins example from your blog post and feed it to afl-fuzz, then wait 2 minutes".
- EuAndreh 7y agoA good follow-up to this would be to get the afl-fuzz error report and send it to the maintainers. Maybe they're not even aware of those problems.
- x0 7y agoif you can be bothered, rebuild it with debug symbols, run it, dump core and try and find exactly where the bug is. I vaguely remember doing this with wget, there was a way to make it think the terminal's width is (unsigned)-4, then when printing the download status to stdout, it clears a buffer with a memset(ptr, ' ', -4). Of course -4 in this context is a huge number. It overwrote its whole self until segfault. (this issue was fixed, btw) great learning experience, for anyone who knows enough C to understand what they're looking at.
- tptacek 7y agoIf I'd done anything significant, I would, but all I did was confirm the suspicion that this old c-language GNU tool hadn't been exhaustively fuzzed. I'm sure the recutils team can do a perfectly fine job fuzzing it themselves.
- intc 7y agoOr perhaps you could write a blog post on how to use a fuzzer so we can all learn from your findings?
- tptacek 7y agoThe Github page for afl-fuzz has a really excellent Getting Started doc.
- intc 7y agoSounds cool. Could you share the link to their official git repo?
- tptacek 7y agohttps://github.com/google/AFL https://github.com/google/AFL
- intc 7y agoHmm. Doesn't look like very "hands on" to me (README.md). Or then I just couldn't find the document you mentioned in the previous post. But I guess one has to learn these things by trial and error then.
- xearl 7y ago> Or then I just couldn't find the document you mentioned in the previous post. There you go: https://github.com/google/AFL/blob/master/docs/QuickStartGuide.txt https://github.com/google/AFL/blob/master/docs/QuickStartGui...