Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fuzzdata 问题 #2

Open
zhaogang92 opened this issue Jul 5, 2018 · 4 comments
Open

Fuzzdata 问题 #2

zhaogang92 opened this issue Jul 5, 2018 · 4 comments

Comments

@zhaogang92
Copy link

大佬好,我看fuzzdata里有些非常大的文件.用这么大的文件做seed input合适吗?在这些文件上的fuzzing速度很慢,AFL文档里也不推荐用大文件.大佬当时是通过这些文件找到bug的吗?

@zhaogang92
Copy link
Author

使用gm1.3.26版本,使用fuzzdata里的文件,没有发现任何crash是为什么呢?(15小时).需要为AFL加asan选项吗?还是fuzz文件不对? @lcatro

@lcatro
Copy link
Owner

lcatro commented Jul 13, 2018

@zhaogang92 其实是不推荐弄大文件的,但是fuzzdata 里面的样本是从另一个地方拿过来的,所以随缘跑一跑.现在GM 都修了不少洞了,应该很少了,去找找其他的库吧.还有你在Fuzzing 的时候用了ASAN 了吗,如果没ASAN 的话找bug 会更加随缘,一般这种情况下我推荐在桌上摆个小物件调和调和风水..

@zhaogang92
Copy link
Author

@lcatro 我跑的应该是和你这个repo里写的一样的版本,不过我只跑了convert读,没跑output.按道理应该是可以找到crash的,但跑了好几次,都没发现.我跑了带ASAN和不带ASAN的,都没发现问题.你当时也是用的fuzzdata文件夹是吧?另外graphicmagic你有发现convert读的crash吗?

@merc1995
Copy link

学到了,我回去摆个小物件调和调和风水:)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants