/*
S-Fuzz - Mutation Based Fuzzer
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
************************************************************************
s4ndman
mail all bugs to: <r[dot]coded[AT]gmail[dot]com>
READFIRST: site link: http://mmaptonull.blogspot.com/2011/02/sfuzz-file-format-fuzzer.html
:::::::CHANGELOG:::::::::
v.1 ~ 05/12/09
-first _simple_ version out
v.3 ~ 07/12/09
-additional options added
+logging added
v.5 ~ 10/12/09
-malloc implementation for [large file sizes]
+auto malloc by calculating file sizes
-improved logging
-bugfixes
v.6 ~ 8/06/10
-sleep timer adder to reduce computation load
-memory corruption bugfixes [multiple _offbyone_ bugs]
v.7 ~ 10/02/11
-implemented header offset
+avoids header region if needed for strict header testing programs
-added verbosity choice for logfile to reduce log file size
TODO: implement data addition mutation option
***********************************************************************/
#include <stdio.h>
#include <string.h>
#include <stdlib.h>
#include <unistd.h>
FILE *fpin, *fpout, *fplog;
main(int argc, char *argv[]){
if (argc < 9){
printf("[*]@@@@__S-Fuzz__@@@@\n");
printf("[*]type: Mutation Fuzzer\n");
printf("[*]by: Sandman, 05/05/2010\n");
printf("[i]usage: ./sfuzz <i> <o> <nf> <fsz> <mbovr> <logf> <slp> <hdr> <vrb>\n");
printf("[i]i > infile\n");
printf("[i]o > outfile\n");
printf("[i]nf > number of files\n");
printf("[i]fsz > max file size (-1 to autocalculate)\n");
printf("[i]mbovr > maximum bytes to overwrite\n");
printf("[i]logf > logfile name to log all actions.\n");
printf("[i]slp > sleep time between file writes [seconds]\n");
printf("[i]hdr > header offset [bytes from beginning, to avoid header corruption by fuzzing]\n");
printf("[i]vrb > logfile verbosity [0=off, 1=on] [to avoid clutter in the logfile]\n");
printf("[!]NOTE: ALL SWITCHES ARE REQUIRED.\n");
exit(1);
}
int vrb, bLoc, rByte, fNumBytes, i, x, nFiles, maxNBytes, nBytes, fMemAllocd, sleepTime, hdrOffset;
printf("%s\n",argv[4]);
char *mainBuf;
char *backupBuf;
char outFile[1024];
sleepTime = atoi(argv[7]);
maxNBytes = atoi(argv[5]);
nFiles = atoi(argv[3]);
hdrOffset = atoi(argv[8]);
vrb = atoi(argv[9]);
fplog = fopen(argv[6], "w");
fprintf(fplog, "[i]starting sfuzz on file %s\n", argv[1]);
fprintf(fplog, "[i]starting with parameters:\n");
fprintf(fplog, "[i]infile: %s\n", argv[1]);
fprintf(fplog, "[i]outfile: %s\n", argv[2]);
fprintf(fplog, "[i]number of fuzzed files: %s\n", argv[3]);
fprintf(fplog, "[i]max file size (autocalculated if -1): %s\n bytes", argv[4]);
fprintf(fplog, "[i]max bytes to overwrite: %s\n bytes", argv[5]);
fprintf(fplog, "[i]log file: %s\n", argv[6]);
fprintf(fplog, "[i]sleep time: %s\n", argv[7]);
fprintf(fplog, "[i]header offset: %s\n bytes", argv[8]);
fprintf(fplog, "[i]logfile verbosity: %s\n", argv[9]);
if ((atoi(argv[4])) == -1){
fpin = fopen(argv[1], "r");
if (fpin == NULL){
printf("[-]infile read error, does it exist??\n");
fprintf(fplog, "[-]error file read error on %s\n", argv[1]);
fclose(fplog);
exit(-1);
}
fseek(fpin, 0, SEEK_END);
fMemAllocd = ftell(fpin);
fprintf(fplog, "[i]file size auto-calculate result: %d bytes\n", fMemAllocd);
fprintf(fplog, "[i]allocating buffer size: %d bytes + 1000 bytes.\n", fMemAllocd);
fclose(fpin);
mainBuf = (char*)malloc(fMemAllocd+1000);
backupBuf = (char*)malloc(fMemAllocd+1000);
if (mainBuf == NULL || backupBuf == NULL){
printf("[-]error: out of memory, malloc failed!\n");
fprintf(fplog,"[-]error: out of memory, malloc failed!\n");
fclose(fplog);
exit(-1);
}
}
else{
mainBuf = (char*)malloc(atoi(argv[4]));
backupBuf = (char*)malloc(atoi(argv[4]));
if (mainBuf == NULL || backupBuf == NULL){
printf("[-]error: out of memory, malloc failed!\n");
fprintf(fplog,"[-]error: out of memory, malloc failed!\n");
fclose(fplog);
exit(-1);
}
fprintf(fplog, "[i]allocating buffer size: %s bytes\n", argv[4]);
}
fpin = fopen(argv[1],"r");
if (fpin == NULL){
printf("[-]infile read error, does it exist??\n");
fprintf(fplog, "[-]error file read error on %s\n", argv[1]);
free(mainBuf);
free(backupBuf);
fclose(fplog);
exit(-1);
}
if ((atoi(argv[4])) == -1){
fNumBytes = read(fileno(fpin), mainBuf, (fMemAllocd+1000));
}
else{
fseek(fpin, 0, SEEK_END);
fMemAllocd = ftell(fpin);
fseek(fpin, 0, SEEK_SET);
if (fMemAllocd > (atoi(argv[4]))){
printf("[!]Warning: Allocated buffer [%d] is less than file size [%d], fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd);
fprintf(fplog,"[!]Warning: Allocated buffer [%d] is less than file size [%d]; fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd);
}
fNumBytes = read(fileno(fpin), mainBuf, (atoi(argv[4])));
}
fclose(fpin);
memcpy(backupBuf, mainBuf, fNumBytes);
for(i=0; i<nFiles; i++){
srand(time(NULL));
nBytes = rand() % maxNBytes;
nBytes++;
printf("[+]Modifying %d byte(s) in copy %d\n", nBytes, i);
fprintf(fplog, "[+]Modifying %d byte(s) in copy %d\n", nBytes, i);
for (x=0; x<nBytes; x++){
rByte = rand() % 257;
bLoc = ((rand() % (fNumBytes-hdrOffset))+hdrOffset) -1;
if (rByte == 256){
rByte = -1;
}
mainBuf[bLoc] = rByte;
if (vrb == 1){
printf("[*]File buffer[%d] orig-byte = %d\n",bLoc, backupBuf[bLoc]);
printf("[*]File buffer[%d] new-byte = %d\n",bLoc, rByte);
fprintf(fplog,"[*]File buffer[%d] orig-byte = %d\n",bLoc, backupBuf[bLoc]);
fprintf(fplog,"[*]File buffer[%d] new-byte = %d\n",bLoc, rByte);}
}
sprintf(outFile, "%d-%s",i,argv[2]);
fpout = fopen(outFile, "w");
write(fileno(fpout), mainBuf, fNumBytes);
printf("[+]Writing file %s\n", outFile);
fprintf(fplog,"[+]Writing file %s\n", outFile);
fclose(fpout);
printf("[-]sleeping %s seconds...\n", argv[7]);
fprintf(fplog,"[-]sleeping %d seconds...", sleepTime);
sleep(sleepTime);
memcpy(mainBuf, backupBuf, fNumBytes);
}
printf("[+]completed creating %d fuzzed files.\n", nFiles);
fprintf(fplog,"[+]completed creating %d fuzzed files.\n", nFiles);
free(mainBuf);
free(backupBuf);
fclose(fplog);
}
Comments
0 B
|👍
/👎