You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于AFL++/QEMU的Android原生库模糊测试报错求助

问题:AFL++/QEMU模糊测试Android原生库时出现超时或崩溃错误

我正按照博客步骤学习AFL++/QEMU与Android原生库的模糊测试,但在最后一步出现超时或崩溃错误。

编译命令

export CC=/home/kali/Android/Sdk/ndk/22.1.7171670/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android30-clang
$CC harness.c -o harness -L/home/kali/Desktop/experimment/research/PoCs/android-afl-qemu/ -lvulnlib -ldl -Wl,--export-dynamic

添加-t 5000后的结果见截图,初始错误截图见另一截图。附上harness代码,请问是否存在遗漏的配置或代码问题?

Harness代码

#include <dlfcn.h>
#include <stdio.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <errno.h>
#include <unistd.h>
#include <stdlib.h>
#include <stdbool.h>

#include <jni.h>


// Structs
struct JniInvocationImpl {
    // Name of library providing JNI_ method implementations.
    const char* jni_provider_library_name;
    // Opaque pointer to shared library from dlopen / LoadLibrary.
    void* jni_provider_library;
    // Function pointers to methods in JNI provider.
    jint (*JNI_GetDefaultJavaVMInitArgs)(void*);
    jint (*JNI_CreateJavaVM)(JavaVM**, JNIEnv**, void*);
    jint (*JNI_GetCreatedJavaVMs)(JavaVM**, jsize, jsize*);
};


// JVM related functions prototypes
typedef jint(*JNI_CreateJavaVM_t)(JavaVM **p_vm, JNIEnv **p_env, void *vm_args);
typedef jint(*registerNatives_t)(JNIEnv *env, jclass clazz);

struct JniInvocationImpl* (*JniInvocationCreate)();
bool (*JniInvocationInit)(struct JniInvocationImpl* instance, const char* library);
void (*JniInvocationDestroy)(struct JniInvocationImpl* instance);


// Harness specific function prototypes.
extern int JNI_OnLoad(JavaVM *vm, void *reserved);
extern jstring Java_com_alephsecurity_jniexample_EchoUtils_sendString(JNIEnv* env, jobject obj , jstring str);


//Globals
struct JniInvocationImpl *invocation;
void *libandroid_runtime_dso;


// Defines
#define ERROR 1

// Empty Functions

JNIEXPORT void InitializeSignalChain()
{

}

JNIEXPORT void ClaimSignalChain()
{

}

JNIEXPORT void UnclaimSignalChain()
{

}

JNIEXPORT void InvokeUserSignalHandler()
{

}

JNIEXPORT void EnsureFrontOfChain()
{

}

JNIEXPORT void AddSpecialSignalHandlerFn()
{

}

JNIEXPORT void RemoveSpecialSignalHandlerFn()
{

}

int init_jvm(JavaVM **p_vm, JNIEnv **p_env)
{
    JNI_CreateJavaVM_t JNI_CreateJavaVM;
    registerNatives_t registerNatives;

    JavaVMInitArgs args;
    JavaVMOption opt[3];

    opt[0].optionString = "-Djava.class.path=/data/local/tmp/harness/app-debug.apk";
    opt[1].optionString = "-Djava.library.path=/data/local/tmp/harness";
    opt[2].optionString = "-verbose:jni"; // may want to remove this, it's noisy

    args.version = JNI_VERSION_1_6;
    args.options = opt;
    args.nOptions = 3;
    args.ignoreUnrecognized = JNI_FALSE;

    libandroid_runtime_dso = dlopen("libandroid_runtime.so", RTLD_NOW);

    if (!libandroid_runtime_dso)
    {
        printf("No libandroid_runtime\n");
        return ERROR;
    }

    JniInvocationCreate = dlsym(libandroid_runtime_dso, "JniInvocationCreate");
    if (!JniInvocationCreate)
    {
        printf("No JniInvocationCreate symbol found\n");
        return ERROR;
    }

    printf("Calling InvocationCreate\n");
    invocation = JniInvocationCreate();

    JniInvocationInit = dlsym(libandroid_runtime_dso, "JniInvocationInit");
    if (!JniInvocationInit)
    {
        printf("No JniInvocationInit symbol found\n");
        return ERROR;
    }

    printf("Calling JniInvocationInit\n");
    JniInvocationInit(invocation, "libandroid_runtime.so");


    JNI_CreateJavaVM = (JNI_CreateJavaVM_t) dlsym(libandroid_runtime_dso, "JNI_CreateJavaVM");
    if (!JNI_CreateJavaVM)
    {
        printf("No JNI_CreateJavaVM symbol found\n");
        return ERROR;
    }

    registerNatives = (registerNatives_t) dlsym(libandroid_runtime_dso, "Java_com_android_internal_util_WithFramework_registerNatives");
    if (!registerNatives)
    {
        // Attempt non-legacy version
        registerNatives = (registerNatives_t) dlsym(libandroid_runtime_dso, "registerFrameworkNatives");
        if(!registerNatives)
        {
            printf("No registerNatives symbol found\n");
            return ERROR;
        }
    }

    printf("Calling Creating javaVM\n");
    if (JNI_CreateJavaVM(&(*p_vm), &(*p_env), &args))
    {
        printf("JNI_CreateJavaVM failed\n");
        return ERROR;
    }

    printf("Calling registerNatives\n");
    if (registerNatives(*p_env, 0))
    {
        printf("registerNatives failed\n");
        return ERROR;
    }

    return 0;
}

int main(void)
{
    int status = 0;
    char buffer[1024] = {0};
    jclass echo_class;
    jobject echo_instance;
    jmethodID constructor_method;
    jstring result, buf_str;

    JavaVM *vm = NULL;
    JNIEnv *env = NULL;


    status = init_jvm(&vm, &env);
    if (0 != status)
    {
        printf("Initialization failure (%i)\n", status);
        return ERROR;
    }
    printf("Initialization success (vm=%p, env=%p)\n", vm, env);

    JniInvocationDestroy = dlsym(libandroid_runtime_dso, "JniInvocationDestroy");
    if (!JniInvocationDestroy)
    {
        return ERROR;
    }

    printf("[+] Finding EchoUtils class\n");
    echo_class = (*env)->FindClass(env, "com.alephsecurity.jniexample.EchoUtils");
    if (NULL == echo_class)
    {
        printf("[!] Couldn't find EchoUtils on the class path\n");
        return ERROR;
    }

    printf("[+] Found EchoUtils class: %p\n", echo_class);

    constructor_method = (*env)->GetMethodID(env, echo_class, "<init>", "()V");
    if (NULL == constructor_method)
    {
        printf("[!] Could not find <init> method\n");
        return ERROR;
    }

    printf("[+] Found <init>: %p\n", constructor_method);


    echo_instance = (*env)->NewObject(env, echo_class, constructor_method);
    if (NULL == echo_instance)
    {
        printf("[!] Couldn't call <init>\n");
        if((*(env))->ExceptionCheck(env))
        {
            printf("Exception occured!");
            (*(env))->ExceptionDescribe(env);
            (*(env))->ExceptionClear(env);
        }
        return ERROR;
    }

    printf("[+] Instantiated EchoUtils class: %p\n", echo_instance);


    read(STDIN_FILENO, buffer, 1024);
    printf("stdin buffer: %s\n", buffer);
    buf_str = (*env)->NewStringUTF(env, buffer);
    printf("calling sendString\n");
    result = Java_com_alephsecurity_jniexample_EchoUtils_sendString(env, echo_instance, buf_str);
    printf("Got result: %p\n", result);
    printf("The result is: %s\n", (*env)->GetStringUTFChars(env, result, NULL));

    printf("[+] Cleaning up VM\n");
    // When fuzzing with fork server don't destroy the JVM
    /**
     (*vm)->DestroyJavaVM(vm);

     printf("Calling JniInvocationDestroy\n");
     JniInvocationDestroy(invocation);

     dlclose(libandroid_runtime_dso);
     **/
    return 0;
}

内容的提问来源于stack exchange,提问作者Boom

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 22:39:53