Comments (5)
It would be also nice to know what the execution speed is without any instrumentation, to establish what the "normal" behavior is.
However, since you are unloading the library every time, it is quite possible that dynamorio has to translate a lot of code anew for every iteration which introduces unnecessary overhead. The way to work around this is:
void fuzz() {
//call functions on a dll
}
int main(int argc, char **argv)
{
hDLL = LoadLibrary("foo");
fuzz()
FreeLibrary(hDLL);
}
And then use the target_offset of fuzz() instead of main().
from winafl.
So basically execution without LoadLibrary() reaches up to 600 exec/sec
When I just LoadLibrary() it drops to 13 exec/sec. You can see below my main function. A very simple Main that basically loads the DLL and free it just to benchmark
int main(int argc, char **argv)
{
char DLL[] = "ABCpdfCE5";
HANDLE Proc;
HINSTANCE hDLL;
int ret;
printf("Attempting to load .DLL...\n");
hDLL = LoadLibrary(DLL);
if(hDLL == NULL)
{
printf("DLL NAME: %s\n", DLL);
printf(".DLL load FAILED!!1\n");
return -1;
}
FreeLibrary(hDLL);//release the DLL library
return 0;
}
And when I start to call functions ... it drops to 0.3 exec/sec to 0.8 exec/sec which is pretty bad. I am not a windows guru but I will try to place the folder where I execute the binary and the DLL in something similar to ramfs in Linux (need to google that). Please if you have any ideas to enhance execution I would love to hear them.
Update: tried the RamDisk on windows .. no improvement!
from winafl.
Yes that does sound pretty slow. What's the execution speed if you just run your target natively? I don't think LoadLibrary should be the bottleneck, but if it is you can only call it once at the beginning of your test program and then create another function that you'd actually fuzz (without calling LoadLibrary for every iteration).
from winafl.
It would be also nice to know what the execution speed is without any instrumentation, to establish what the "normal" behavior is.
That's why I tested a simple hellow_World app and got the execution speed to be around 600 exec/sec
I will try your suggested solutions, seems very tempting!
Btw, will DynamoRIO be able to instrument the code if the binary was written in .NET? a C# code basically?? (I think no!)
from winafl.
However, since you are unloading the library every time, it is quite possible that dynamorio has to translate a lot of code anew for every iteration which introduces unnecessary overhead. The way to work around this is:
void fuzz() {
//call functions on a dll
}
int main(int argc, char **argv)
{
hDLL = LoadLibrary("foo");
fuzz()
FreeLibrary(hDLL);
}
And then use the target_offset of fuzz() instead of main().
That was it. This basically enhanced the fuzzing speed from 7 exec/sec to 200 exec/sec .. which isn't bad.
from winafl.
Related Issues (20)
- WinAFL Internal Crash at PC 0x5a1a456e HOT 6
- PROGRAM ABORT : Unexpected result from pipe! expected 'P', instead received '' HOT 1
- ERROR while building winafl HOT 1
- Error: Can't open .cur_input
- drrun.exe and afl-fuzz.exe giving error when -fsanitize=address flag given to compile target
- PROGRAM ABORT : Test case 'id_000000' results in a crash HOT 3
- Occur time out when init test case
- Incorrect detection count threads on multiCPU motherboards HOT 2
- Winafl doesn't want to start, reading other issues didn't help
- PROGRAM ABORT : CreateNamedPipe failed, GLE=231 HOT 2
- tmin: Proposing del_len option for improved speed HOT 2
- Is dumb mode (-n) currently implemented? HOT 4
- My output keeps showing a timeout HOT 8
- problem about finding crashes HOT 6
- not running under DR HOT 4
- No expected output when using standalone debug mode of WinAFL client HOT 3
- WinAFL internal crash HOT 2
- winafl.dll : fatal error LNK1120 HOT 2
- Timeout Options Madness HOT 2
- Unable to load client library: winafl.dll: library initializer failed.. HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from winafl.