If you want to start now to fuzz Android native libraries I've just merged a @quarkslab QBDI based mode for Android fuzzing from hac425xxx. For fuzzing both native and generated code, Frida mode will be here ASAP ;)https://github.com/vanhauser-thc/AFLplusplus/tree/master/qbdi_mode …
-
-
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Sounds like you'd need to be quite careful about picking what you want to harness this way, pretty limited to stateless parsing code? Could you fix state, free allocations the target makes, close fds, etc at the end of one persistent loop in frida? Pretty cool if so :)
-
yep my simple script is pure persistent fuzzing now. probably i'll implement also a forkserver. For allocations/fds can be done simply hooking *alloc/open but of course has a cost that can be huge if the application heavily uses such functions.
Kraj razgovora
Novi razgovor -
-
-
Awesome! How does this improve over the existing persistent-mode implementation?
-
It doesn't. QEMU persistent mode is faster (but only for x86), the benefit of using Frida is the binary instrumentation of mobile apps. The frida_mode AFL++ will problably targets only mobile devices, for the other options there is already QEMU.
Kraj razgovora
Novi razgovor -
-
-
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
What is performant in memory fuzzing?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.