5 ms·
if you can be bothered, rebuild it with debug symbols, run it, dump core and try and find exactly where the bug is. I vaguely remember doing this with wget, th
by x0 7y ago
if you can be bothered, rebuild it with debug symbols, run it, dump core and try and find exactly where the bug is.
I vaguely remember doing this with wget, there was a way to make it think the terminal's width is (unsigned)-4, then when printing the download status to stdout, it clears a buffer with a memset(ptr, ' ', -4). Of course -4 in this context is a huge number. It overwrote its whole self until segfault. (this issue was fixed, btw)
great learning experience, for anyone who knows enough C to understand what they're looking at.
- tptacek 7y agoIf I'd done anything significant, I would, but all I did was confirm the suspicion that this old c-language GNU tool hadn't been exhaustively fuzzed. I'm sure the recutils team can do a perfectly fine job fuzzing it themselves.
- intc 7y agoOr perhaps you could write a blog post on how to use a fuzzer so we can all learn from your findings?
- tptacek 7y agoThe Github page for afl-fuzz has a really excellent Getting Started doc.
- intc 7y agoSounds cool. Could you share the link to their official git repo?
- tptacek 7y agohttps://github.com/google/AFL https://github.com/google/AFL
- intc 7y agoHmm. Doesn't look like very "hands on" to me (README.md). Or then I just couldn't find the document you mentioned in the previous post. But I guess one has to learn these things by trial and error then.
- xearl 7y ago> Or then I just couldn't find the document you mentioned in the previous post. There you go: https://github.com/google/AFL/blob/master/docs/QuickStartGuide.txt https://github.com/google/AFL/blob/master/docs/QuickStartGui...
- ibotty 7y agoIt did not take me much time to find https://github.com/google/AFL/blob/master/docs/QuickStartGuide.txt https://github.com/google/AFL/blob/master/docs/QuickStartGui... which I guess is the doc he referenced.
- cpach 7y agoFor those looking for tutorials; in addition to the one already linked, I’m quite sure there are quite a few decent YouTube videos about fuzzing with AFL.
- namibj 7y agohttps://llvm.org/docs/LibFuzzer.html https://llvm.org/docs/LibFuzzer.html might also be quite interesting due to the potentially significantly higher fuzzing speed (no fork(2) for each try).
- jcims 7y agoSomething about this request gets under my skin like nothing I've read on HN in a very long time.
- tptacek 7y agoIt was weird. I decided to take it as a compliment. But as it's an unearned one, I think I probably won't write a blog post about it.
- keeganpoppen 7y agoNO WE MUST ALL LEARN FROM YOUR FINDINGS
- intc 7y agoIndeed it's a compliment. And also a humble request because I'm interested in this subject. Perhaps my way of expression was not the best? But I'll take some time to see what other resources are available there.
- tptacek 7y agoI'm serious that you can read the (excellent) Quick Start for AFL, pick a C program (try recutils!) and get afl-fuzz running very quickly, and it's really sort of self-explanatory once it's running. It's a really well-built piece of software.
- cpach 7y agoSometimes people write strange things ¯\_(ツ)_/¯