Sign inSign up

zjuchenyuan/mopt

By zjuchenyuan

•Updated about 7 years ago

MOPT: Optimized Mutation Scheduling for Fuzzers

Image
0

3.0K

zjuchenyuan/mopt repository overview

⁠MOpt

https://hub.docker.com/r/zjuchenyuan/mopt⁠

Source: https://github.com/puppet-meteor/MOpt-AFL⁠

Version: 2.52b
Last Update: 2019/08
Type: AFL-based
Tag: Mutation Strategy Selection, PSO Algorithm

⁠Guidance

Welcome to the world of fuzzing! In this tutorial, we will experience a simple realistic fuzzing towards MP3Gain⁠ 1.6.2.

⁠Step1: System configuration
echo "" | sudo tee /proc/sys/kernel/core_pattern
echo 0 | sudo tee /proc/sys/kernel/core_uses_pid
echo performance | sudo tee /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor
echo 0 | sudo tee /proc/sys/kernel/yama/ptrace_scope
echo 1 | sudo tee /proc/sys/kernel/sched_child_runs_first
echo 0 | sudo tee /proc/sys/kernel/randomize_va_space

Error message like No such file or directory is fine, and you can just ignore it.

Note:

Although not all configuration are required by this fuzzer, we provide these command in a uniform manner for consistency between different fuzzers.

These commands may impair your system security (turning off ASLR), but not a big problem since fuzzing experiments are normally conducted in dedicated machines.

Instead of echo core > /proc/sys/kernel/core_pattern given by many fuzzers which still generate a core dump file when crash happens, here we disable core dump file generation to reduce I/O pressure during fuzzing. Ref⁠.

⁠Step2: Compile target programs

Since MOPT is based on AFL, this step is equal to AFL Guidance⁠.

Download the source code, compile using afl-gcc.

wget https://sourceforge.net/projects/mp3gain/files/mp3gain/1.6.2/mp3gain-1_6_2-src.zip/download -O mp3gain-1_6_2-src.zip
mkdir -p mp3gain1.6.2 && cd mp3gain1.6.2
unzip ../mp3gain-1_6_2-src.zip
# build using afl-gcc
docker run --rm -w /work -it -v `pwd`:/work --privileged zjuchenyuan/afl \
    sh -c "make clean; make"
⁠Step3: Prepare Seed Files

UNIFUZZ⁠ provides seed files with various types. Here we provides 10 mp3 seed files, to be downloaded to seed_mp3 folder.

# apt install -y subversion
svn export https://github.com/UNIFUZZ/dockerized_fuzzing_examples/trunk/seed/mp3 seed_mp3
⁠Step4: Fuzzing!

Here we assume you have built mp3gain binary in current folder and downloaded mp3 seed files.

mkdir -p output/mopt
docker run --rm --privileged -it -w /work -it -v `pwd`:/work zjuchenyuan/mopt \
    afl-fuzz -L 0 -i seed_mp3 -o output/mopt -- ./mp3gain @@

⁠Paper

USENIX 2019: MOPT: Optimized Mutation Scheduling for Fuzzers PDF⁠

Tag summary

Content type

Image

Digest

Size

444.2 MB

Last updated

about 7 years ago

docker pull zjuchenyuan/mopt