[!] Stopped during the first cycle, results may be incomplete. (For info on resuming, see /usr/local/share/doc/afl/README.md) [*] Writing ./out/default/fastresume.bin ... [+] fastresume.bin successfully written with 9453487 bytes. [+] We're done here. Have a nice day!
今天的 Fuzz 格外的漫长啊,花了我接近八个小时,只出现了一个独特错误。
不过经过验证调用链,这个崩溃正好是我们需要的CVE-2017-13028 :
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
==2586765==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x5120000002d9 at pc 0x5555557d5b1c bp 0x7fffffffd9e0 sp 0x7fffffffd188 READ of size 4 at 0x5120000002d9 thread T0 #0 0x5555557d5b1b in MemcmpInterceptorCommon(void*, int (*)(void const*, void const*, unsigned long), void const*, void const*, unsigned long) crtstuff.c #1 0x5555557d5ff0 in memcmp (/home/zlsf/fuzz_main/install/sbin/tcpdump+0x281ff0) (BuildId: b2a754f7d67207d8) #2 0x555555937998 in bootp_print /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print-bootp.c:382:6 #3 0x5555559e8a6d in ip_print_demux /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print-ip.c:402:3 #4 0x5555559f05e0 in ip_print /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print-ip.c:673:3 #5 0x55555598879d in ethertype_print /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print-ether.c:333:10 #6 0x555555986621 in ether_print /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print-ether.c:236:7 #7 0x5555558ac2ef in pretty_print_packet /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./print.c:332:18 #8 0x5555558ac2ef in print_packet /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./tcpdump.c:2497:2 #9 0x555555dcba7c in pcap_offline_read /home/zlsf/fuzz_main/libpcap-1.8.0/./savefile.c:507:4 #10 0x5555558a24ba in pcap_loop /home/zlsf/fuzz_main/libpcap-1.8.0/./pcap.c:875:8 #11 0x5555558a24ba in main /home/zlsf/fuzz_main/tcpdump-tcpdump-4.9.2/./tcpdump.c:2000:12 #12 0x7ffff762a1c9 in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16 #13 0x7ffff762a28a in __libc_start_main csu/../csu/libc-start.c:360:3 #14 0x5555557b93c4 in _start (/home/zlsf/fuzz_main/install/sbin/tcpdump+0x2653c4) (BuildId: b2a754f7d67207d8)