Comments (2)
Nice catch! This indeed looks like a bug.
Unfortunately I'm travelling for another week or so and don't have my Windows machine with me, so realistically I'm going to release a new version with the fix on the week of August 22.
Without updating the previous_offset, what we are getting out of WinAFL is essentially basic block coverage instead of edge coverage, so it's not a complete disaster but certainly not what the author intended :-)
from winafl.
The good news is that this is now fixed and edge coverage seems to be working.
The bad news is that edge coverage doesn't behave as well as expected, apparently through no fault of WinAFL. The problem is that if any of the coverage modules executes two or more threads at the same time, every new context switch is going to be (wrongly) interpreted as new coverage. For example, test_gdiplus fuzz in edge coverage mode is quickly going to produce hundreds of new samples, when in reality only few of those are going to contain new coverage. This is unfortunate because on a casual look the app doesn't appear to require multiple threads. On the other hand, a more simple test.exe fuzz is going to run equally well in both bb and edge coverage mode.
As a result of this I decided to use bb mode as the default, in order for the default settings to work well for more applications (this can be changed by setting the -covtype edge instrumentation flag, of course).
from winafl.
Related Issues (20)
- Update docs HOT 3
- Facing Issues with Offset Calculation and Starting Fuzzing in WinAFL HOT 2
- Compilation failed HOT 3
- Documented build commands do not generate winafl.dll HOT 9
- How to stop WinAFL properly? HOT 1
- Winafl + Libprotobuf-mutator
- WinAFL Internal Crash at PC 0x5a1a456e HOT 6
- PROGRAM ABORT : Unexpected result from pipe! expected 'P', instead received '' HOT 1
- ERROR while building winafl HOT 1
- Error: Can't open .cur_input
- drrun.exe and afl-fuzz.exe giving error when -fsanitize=address flag given to compile target
- PROGRAM ABORT : Test case 'id_000000' results in a crash HOT 3
- Occur time out when init test case
- Incorrect detection count threads on multiCPU motherboards HOT 2
- Winafl doesn't want to start, reading other issues didn't help
- PROGRAM ABORT : CreateNamedPipe failed, GLE=231 HOT 2
- tmin: Proposing del_len option for improved speed HOT 2
- Is dumb mode (-n) currently implemented? HOT 4
- My output keeps showing a timeout HOT 8
- problem about finding crashes HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from winafl.