IsraelTorres icon

s4ndman-sfuzz

IsraelTorres | PRO | 05/27/11 09:41:20 PM UTC | 0 ⭐ | 472 👁️ | Never ⏰ | []
C |

6.94 KB

|

None

|

0 👍

/

0 👎

/*
    S-Fuzz - Mutation Based Fuzzer
 
    This program is free software: you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation, either version 3 of the License, or
    (at your option) any later version.
 
    This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.
 
    You should have received a copy of the GNU General Public License
    along with this program.  If not, see <http://www.gnu.org/licenses/>.
************************************************************************
 s4ndman
 mail all bugs to: <r[dot]coded[AT]gmail[dot]com>
 READFIRST: site link: http://mmaptonull.blogspot.com/2011/02/sfuzz-file-format-fuzzer.html
 
:::::::CHANGELOG:::::::::
 
v.1 ~ 05/12/09 
  -first _simple_ version out
  
v.3 ~ 07/12/09
  -additional options added
    +logging added
    
 
v.5 ~ 10/12/09
  -malloc implementation for [large file sizes]
    +auto malloc by calculating file sizes
  -improved logging
  -bugfixes
 
v.6 ~ 8/06/10
  -sleep timer adder to reduce computation load
  -memory corruption bugfixes [multiple _offbyone_ bugs]
 
v.7 ~ 10/02/11
  -implemented header offset
   +avoids header region if needed for strict header testing programs
  -added verbosity choice for logfile to reduce log file size
  
TODO: implement data addition mutation option 
***********************************************************************/
 
#include <stdio.h>
#include <string.h>
#include <stdlib.h>
#include <unistd.h>
 
FILE *fpin, *fpout, *fplog;
 
main(int argc, char *argv[]){
    
    if (argc < 9){
        printf("[*]@@@@__S-Fuzz__@@@@\n");
        printf("[*]type: Mutation Fuzzer\n");
        printf("[*]by: Sandman, 05/05/2010\n");
        printf("[i]usage: ./sfuzz <i> <o> <nf> <fsz> <mbovr> <logf> <slp> <hdr> <vrb>\n");
        printf("[i]i     > infile\n");
        printf("[i]o     > outfile\n");
        printf("[i]nf    > number of files\n");
        printf("[i]fsz   > max file size (-1 to autocalculate)\n");
        printf("[i]mbovr > maximum bytes to overwrite\n");
        printf("[i]logf  > logfile name to log all actions.\n");
        printf("[i]slp   > sleep time between file writes [seconds]\n");
        printf("[i]hdr   > header offset [bytes from beginning, to avoid header corruption by fuzzing]\n");
        printf("[i]vrb   > logfile verbosity [0=off, 1=on]  [to avoid clutter in the logfile]\n");
        printf("[!]NOTE: ALL SWITCHES ARE REQUIRED.\n");
        exit(1);
        }
        
    int vrb, bLoc, rByte, fNumBytes, i, x, nFiles, maxNBytes, nBytes, fMemAllocd, sleepTime, hdrOffset;
    printf("%s\n",argv[4]);
    char *mainBuf;
    char *backupBuf;
    char outFile[1024];
    sleepTime = atoi(argv[7]);
    maxNBytes = atoi(argv[5]);
    nFiles = atoi(argv[3]);
    hdrOffset = atoi(argv[8]);
    vrb = atoi(argv[9]);
    
    fplog = fopen(argv[6], "w");
    
    fprintf(fplog, "[i]starting sfuzz on file %s\n", argv[1]);
    fprintf(fplog, "[i]starting with parameters:\n");
    fprintf(fplog, "[i]infile: %s\n", argv[1]);
    fprintf(fplog, "[i]outfile: %s\n", argv[2]);
    fprintf(fplog, "[i]number of fuzzed files: %s\n", argv[3]);
    fprintf(fplog, "[i]max file size (autocalculated if -1): %s\n bytes", argv[4]);
    fprintf(fplog, "[i]max bytes to overwrite: %s\n bytes", argv[5]);
    fprintf(fplog, "[i]log file: %s\n", argv[6]);
    fprintf(fplog, "[i]sleep time: %s\n", argv[7]);
    fprintf(fplog, "[i]header offset: %s\n bytes", argv[8]);
    fprintf(fplog, "[i]logfile verbosity: %s\n", argv[9]);
 
    
    if ((atoi(argv[4])) == -1){
        fpin = fopen(argv[1], "r");
        if (fpin == NULL){
            printf("[-]infile read error, does it exist??\n");
            fprintf(fplog, "[-]error file read error on %s\n", argv[1]);
            fclose(fplog);
            exit(-1);
        }
        fseek(fpin, 0, SEEK_END);
        fMemAllocd = ftell(fpin);
        fprintf(fplog, "[i]file size auto-calculate result: %d bytes\n", fMemAllocd);
        fprintf(fplog, "[i]allocating buffer size: %d bytes + 1000 bytes.\n", fMemAllocd);
        fclose(fpin);
        mainBuf = (char*)malloc(fMemAllocd+1000);
        backupBuf = (char*)malloc(fMemAllocd+1000);
        if (mainBuf == NULL || backupBuf == NULL){
            printf("[-]error: out of memory, malloc failed!\n");
            fprintf(fplog,"[-]error: out of memory, malloc failed!\n");
            fclose(fplog);
            exit(-1);
            }
    }
    else{
        mainBuf = (char*)malloc(atoi(argv[4]));
        backupBuf = (char*)malloc(atoi(argv[4]));
        if (mainBuf == NULL || backupBuf == NULL){
            printf("[-]error: out of memory, malloc failed!\n");
            fprintf(fplog,"[-]error: out of memory, malloc failed!\n");
            fclose(fplog);
            exit(-1);
            }
        fprintf(fplog, "[i]allocating buffer size: %s bytes\n", argv[4]);
        }
    
    fpin = fopen(argv[1],"r");
    if (fpin == NULL){
            printf("[-]infile read error, does it exist??\n");
            fprintf(fplog, "[-]error file read error on %s\n", argv[1]);
            free(mainBuf);
            free(backupBuf);
            fclose(fplog);
            exit(-1);
        }
    if ((atoi(argv[4])) == -1){
        fNumBytes = read(fileno(fpin), mainBuf, (fMemAllocd+1000));
        }
    else{
        fseek(fpin, 0, SEEK_END);
        fMemAllocd = ftell(fpin);
        fseek(fpin, 0, SEEK_SET);
        if (fMemAllocd > (atoi(argv[4]))){
            printf("[!]Warning: Allocated buffer [%d] is less than file size [%d], fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd);
            fprintf(fplog,"[!]Warning: Allocated buffer [%d] is less than file size [%d]; fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd);
            }
        fNumBytes = read(fileno(fpin), mainBuf, (atoi(argv[4])));
        }
        
    fclose(fpin);
    
    memcpy(backupBuf, mainBuf, fNumBytes);
    
    for(i=0; i<nFiles; i++){
        
        srand(time(NULL));
        nBytes = rand() % maxNBytes;
        nBytes++;
        
        printf("[+]Modifying %d byte(s) in copy %d\n", nBytes, i);
        fprintf(fplog, "[+]Modifying %d byte(s) in copy %d\n", nBytes, i);
        
        for (x=0; x<nBytes; x++){
            rByte = rand() % 257;
            bLoc = ((rand() % (fNumBytes-hdrOffset))+hdrOffset) -1;
            
            if (rByte == 256){
                rByte = -1;
                }
                
            mainBuf[bLoc] = rByte;
            if (vrb == 1){
                printf("[*]File buffer[%d] orig-byte = %d\n",bLoc, backupBuf[bLoc]); 
                printf("[*]File buffer[%d] new-byte = %d\n",bLoc, rByte);
                fprintf(fplog,"[*]File buffer[%d] orig-byte = %d\n",bLoc, backupBuf[bLoc]); 
                fprintf(fplog,"[*]File buffer[%d] new-byte = %d\n",bLoc, rByte);}
        }
            
            sprintf(outFile, "%d-%s",i,argv[2]);
            fpout = fopen(outFile, "w");
            write(fileno(fpout), mainBuf, fNumBytes);
            printf("[+]Writing file %s\n", outFile);
            fprintf(fplog,"[+]Writing file %s\n", outFile);
            fclose(fpout);
            printf("[-]sleeping %s seconds...\n", argv[7]);
            fprintf(fplog,"[-]sleeping %d seconds...", sleepTime);
            sleep(sleepTime);
            
            memcpy(mainBuf, backupBuf, fNumBytes);
    }
    
    printf("[+]completed creating %d fuzzed files.\n", nFiles);
    fprintf(fplog,"[+]completed creating %d fuzzed files.\n", nFiles);
    free(mainBuf);
    free(backupBuf);
    fclose(fplog);
}

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎