‹ 首页

performing-fuzzing-with-aflplusplus

@xalgord · 收录于 昨天 · 上游提交 昨天

Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with afl-fuzz, and triages crashes using CASR or GDB scripts. Activates for requests involving binary fuzzing, crash discovery, coverage-guided testing, or AFL++ fuzzing campaigns.

适合你,如果需要通过模糊测试自动挖掘二进制程序中的潜在漏洞

/ 通过 npx 安装 校验哈希
npx oh-my-skill add xalgord/xalgorix/performing-fuzzing-with-aflplusplus
/ 通过 bash 安装
curl -fsSL https://oh-my-skill.com/install.sh | bash -s -- xalgord/xalgorix/performing-fuzzing-with-aflplusplus
/ 已经装过?验证本机副本,不用重装
npx oh-my-skill verify xalgord/xalgorix/performing-fuzzing-with-aflplusplus
安装目标可用 --agent / --scope 或 --to 明确指定;省略时只会在唯一已存在的 agent 目录上自动选择,零命中或多命中会停止并提示。content_hash 缺失或不一致均拒装。
807GitHub stars
~844上下文体积 · 单文件
索引托管

怎么用

技能原文 SKILL.md作者撰写 · MIT · eeaf26b

Performing Fuzzing with AFL++

Overview

AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided fuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode for binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes advanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving, and persistent mode for high-throughput fuzzing.

When to Use
  • When conducting security assessments that involve performing fuzzing with aflplusplus
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing
Common Misconfigurations & Verification

A campaign that runs for hours with zero crashes is usually a setup problem, not a secure target.

  • No sanitizer, so bugs go silent: instrument with AFL_USE_ASAN=1 afl-cc (or afl-clang-fast). Without ASAN/UBSAN a heap overflow corrupts memory without crashing and AFL++ never flags it.
  • Empty or trivial seed corpus: starting -i with one tiny file leaves the fuzzer unable to reach parser logic. Provide diverse valid inputs, then prune with afl-cmin, and shrink each with afl-tmin.
  • No dictionary for structured formats: without -x dict/ (magic bytes, keywords, tokens) AFL++ wastes cycles guessing format headers. Supply a format dictionary.
  • Single-core run wastes the box: use -M main + several -S sec1 sec2 ... secondaries to fuzz in parallel and share finds via the sync dir.
  • Coverage stall ignored: map density flat and pending near zero for hours means saturation — add CMPLOG (-c), MOpt, or new seeds rather than letting it spin.

Verify the harness can actually find bugs: compile a build with a planted bug (e.g. an unchecked strcpy on input) and confirm AFL++ surfaces it in crashes/ within minutes and that afl-tmin + CASR/GDB reproduce it. If the planted bug is never found, fix instrumentation/seeds before trusting a clean run.

Prerequisites
  • AFL++ installed (apt install afl++ or build from source)
  • Target binary source code (for compile-time instrumentation) or QEMU mode for binary-only
  • Initial seed corpus of valid inputs for the target format
  • Linux system with /proc/sys/kernel/core_pattern configured
Steps
  1. Instrument the target binary with afl-cc or afl-clang-fast
  2. Prepare seed corpus directory with minimal valid inputs
  3. Minimize corpus with afl-cmin to remove redundant seeds
  4. Run afl-fuzz with appropriate flags (-i input -o output)
  5. Monitor fuzzing progress via afl-whatsup and UI stats
  6. Triage crashes with afl-tmin minimization and CASR/GDB analysis
  7. Report unique crashes with reproduction steps
Expected Output
+++ Findings +++
  unique crashes: 12
  unique hangs: 3
  last crash: 00:02:15 ago
+++ Coverage +++
  map density: 4.23% / 8.41%
  paths found: 1847
  exec speed: 2145/sec
按 MIT 许可原样转载,未经改动 · 在 GitHub 查看 →

评论

登录即可评论;带「已验证安装」的,是发布者名下有本店的安装或持有记录。