/* S-Fuzz - Mutation Based Fuzzer This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . ************************************************************************ s4ndman mail all bugs to: READFIRST: site link: http://mmaptonull.blogspot.com/2011/02/sfuzz-file-format-fuzzer.html :::::::CHANGELOG::::::::: v.1 ~ 05/12/09 -first _simple_ version out v.3 ~ 07/12/09 -additional options added +logging added v.5 ~ 10/12/09 -malloc implementation for [large file sizes] +auto malloc by calculating file sizes -improved logging -bugfixes v.6 ~ 8/06/10 -sleep timer adder to reduce computation load -memory corruption bugfixes [multiple _offbyone_ bugs] v.7 ~ 10/02/11 -implemented header offset +avoids header region if needed for strict header testing programs -added verbosity choice for logfile to reduce log file size TODO: implement data addition mutation option ***********************************************************************/ #include #include #include #include FILE *fpin, *fpout, *fplog; main(int argc, char *argv[]){ if (argc < 9){ printf("[*]@@@@__S-Fuzz__@@@@\n"); printf("[*]type: Mutation Fuzzer\n"); printf("[*]by: Sandman, 05/05/2010\n"); printf("[i]usage: ./sfuzz \n"); printf("[i]i > infile\n"); printf("[i]o > outfile\n"); printf("[i]nf > number of files\n"); printf("[i]fsz > max file size (-1 to autocalculate)\n"); printf("[i]mbovr > maximum bytes to overwrite\n"); printf("[i]logf > logfile name to log all actions.\n"); printf("[i]slp > sleep time between file writes [seconds]\n"); printf("[i]hdr > header offset [bytes from beginning, to avoid header corruption by fuzzing]\n"); printf("[i]vrb > logfile verbosity [0=off, 1=on] [to avoid clutter in the logfile]\n"); printf("[!]NOTE: ALL SWITCHES ARE REQUIRED.\n"); exit(1); } int vrb, bLoc, rByte, fNumBytes, i, x, nFiles, maxNBytes, nBytes, fMemAllocd, sleepTime, hdrOffset; printf("%s\n",argv[4]); char *mainBuf; char *backupBuf; char outFile[1024]; sleepTime = atoi(argv[7]); maxNBytes = atoi(argv[5]); nFiles = atoi(argv[3]); hdrOffset = atoi(argv[8]); vrb = atoi(argv[9]); fplog = fopen(argv[6], "w"); fprintf(fplog, "[i]starting sfuzz on file %s\n", argv[1]); fprintf(fplog, "[i]starting with parameters:\n"); fprintf(fplog, "[i]infile: %s\n", argv[1]); fprintf(fplog, "[i]outfile: %s\n", argv[2]); fprintf(fplog, "[i]number of fuzzed files: %s\n", argv[3]); fprintf(fplog, "[i]max file size (autocalculated if -1): %s\n bytes", argv[4]); fprintf(fplog, "[i]max bytes to overwrite: %s\n bytes", argv[5]); fprintf(fplog, "[i]log file: %s\n", argv[6]); fprintf(fplog, "[i]sleep time: %s\n", argv[7]); fprintf(fplog, "[i]header offset: %s\n bytes", argv[8]); fprintf(fplog, "[i]logfile verbosity: %s\n", argv[9]); if ((atoi(argv[4])) == -1){ fpin = fopen(argv[1], "r"); if (fpin == NULL){ printf("[-]infile read error, does it exist??\n"); fprintf(fplog, "[-]error file read error on %s\n", argv[1]); fclose(fplog); exit(-1); } fseek(fpin, 0, SEEK_END); fMemAllocd = ftell(fpin); fprintf(fplog, "[i]file size auto-calculate result: %d bytes\n", fMemAllocd); fprintf(fplog, "[i]allocating buffer size: %d bytes + 1000 bytes.\n", fMemAllocd); fclose(fpin); mainBuf = (char*)malloc(fMemAllocd+1000); backupBuf = (char*)malloc(fMemAllocd+1000); if (mainBuf == NULL || backupBuf == NULL){ printf("[-]error: out of memory, malloc failed!\n"); fprintf(fplog,"[-]error: out of memory, malloc failed!\n"); fclose(fplog); exit(-1); } } else{ mainBuf = (char*)malloc(atoi(argv[4])); backupBuf = (char*)malloc(atoi(argv[4])); if (mainBuf == NULL || backupBuf == NULL){ printf("[-]error: out of memory, malloc failed!\n"); fprintf(fplog,"[-]error: out of memory, malloc failed!\n"); fclose(fplog); exit(-1); } fprintf(fplog, "[i]allocating buffer size: %s bytes\n", argv[4]); } fpin = fopen(argv[1],"r"); if (fpin == NULL){ printf("[-]infile read error, does it exist??\n"); fprintf(fplog, "[-]error file read error on %s\n", argv[1]); free(mainBuf); free(backupBuf); fclose(fplog); exit(-1); } if ((atoi(argv[4])) == -1){ fNumBytes = read(fileno(fpin), mainBuf, (fMemAllocd+1000)); } else{ fseek(fpin, 0, SEEK_END); fMemAllocd = ftell(fpin); fseek(fpin, 0, SEEK_SET); if (fMemAllocd > (atoi(argv[4]))){ printf("[!]Warning: Allocated buffer [%d] is less than file size [%d], fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd); fprintf(fplog,"[!]Warning: Allocated buffer [%d] is less than file size [%d]; fuzzed files will be truncated.\n", (atoi(argv[4])), fMemAllocd); } fNumBytes = read(fileno(fpin), mainBuf, (atoi(argv[4]))); } fclose(fpin); memcpy(backupBuf, mainBuf, fNumBytes); for(i=0; i