基于AFL++/QEMU的Android原生库模糊测试报错求助
问题:AFL++/QEMU模糊测试Android原生库时出现超时或崩溃错误
我正按照博客步骤学习AFL++/QEMU与Android原生库的模糊测试,但在最后一步出现超时或崩溃错误。
编译命令
export CC=/home/kali/Android/Sdk/ndk/22.1.7171670/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android30-clang $CC harness.c -o harness -L/home/kali/Desktop/experimment/research/PoCs/android-afl-qemu/ -lvulnlib -ldl -Wl,--export-dynamic
添加-t 5000后的结果见截图,初始错误截图见另一截图。附上harness代码,请问是否存在遗漏的配置或代码问题?
Harness代码
#include <dlfcn.h> #include <stdio.h> #include <sys/types.h> #include <sys/stat.h> #include <fcntl.h> #include <errno.h> #include <unistd.h> #include <stdlib.h> #include <stdbool.h> #include <jni.h> // Structs struct JniInvocationImpl { // Name of library providing JNI_ method implementations. const char* jni_provider_library_name; // Opaque pointer to shared library from dlopen / LoadLibrary. void* jni_provider_library; // Function pointers to methods in JNI provider. jint (*JNI_GetDefaultJavaVMInitArgs)(void*); jint (*JNI_CreateJavaVM)(JavaVM**, JNIEnv**, void*); jint (*JNI_GetCreatedJavaVMs)(JavaVM**, jsize, jsize*); }; // JVM related functions prototypes typedef jint(*JNI_CreateJavaVM_t)(JavaVM **p_vm, JNIEnv **p_env, void *vm_args); typedef jint(*registerNatives_t)(JNIEnv *env, jclass clazz); struct JniInvocationImpl* (*JniInvocationCreate)(); bool (*JniInvocationInit)(struct JniInvocationImpl* instance, const char* library); void (*JniInvocationDestroy)(struct JniInvocationImpl* instance); // Harness specific function prototypes. extern int JNI_OnLoad(JavaVM *vm, void *reserved); extern jstring Java_com_alephsecurity_jniexample_EchoUtils_sendString(JNIEnv* env, jobject obj , jstring str); //Globals struct JniInvocationImpl *invocation; void *libandroid_runtime_dso; // Defines #define ERROR 1 // Empty Functions JNIEXPORT void InitializeSignalChain() { } JNIEXPORT void ClaimSignalChain() { } JNIEXPORT void UnclaimSignalChain() { } JNIEXPORT void InvokeUserSignalHandler() { } JNIEXPORT void EnsureFrontOfChain() { } JNIEXPORT void AddSpecialSignalHandlerFn() { } JNIEXPORT void RemoveSpecialSignalHandlerFn() { } int init_jvm(JavaVM **p_vm, JNIEnv **p_env) { JNI_CreateJavaVM_t JNI_CreateJavaVM; registerNatives_t registerNatives; JavaVMInitArgs args; JavaVMOption opt[3]; opt[0].optionString = "-Djava.class.path=/data/local/tmp/harness/app-debug.apk"; opt[1].optionString = "-Djava.library.path=/data/local/tmp/harness"; opt[2].optionString = "-verbose:jni"; // may want to remove this, it's noisy args.version = JNI_VERSION_1_6; args.options = opt; args.nOptions = 3; args.ignoreUnrecognized = JNI_FALSE; libandroid_runtime_dso = dlopen("libandroid_runtime.so", RTLD_NOW); if (!libandroid_runtime_dso) { printf("No libandroid_runtime\n"); return ERROR; } JniInvocationCreate = dlsym(libandroid_runtime_dso, "JniInvocationCreate"); if (!JniInvocationCreate) { printf("No JniInvocationCreate symbol found\n"); return ERROR; } printf("Calling InvocationCreate\n"); invocation = JniInvocationCreate(); JniInvocationInit = dlsym(libandroid_runtime_dso, "JniInvocationInit"); if (!JniInvocationInit) { printf("No JniInvocationInit symbol found\n"); return ERROR; } printf("Calling JniInvocationInit\n"); JniInvocationInit(invocation, "libandroid_runtime.so"); JNI_CreateJavaVM = (JNI_CreateJavaVM_t) dlsym(libandroid_runtime_dso, "JNI_CreateJavaVM"); if (!JNI_CreateJavaVM) { printf("No JNI_CreateJavaVM symbol found\n"); return ERROR; } registerNatives = (registerNatives_t) dlsym(libandroid_runtime_dso, "Java_com_android_internal_util_WithFramework_registerNatives"); if (!registerNatives) { // Attempt non-legacy version registerNatives = (registerNatives_t) dlsym(libandroid_runtime_dso, "registerFrameworkNatives"); if(!registerNatives) { printf("No registerNatives symbol found\n"); return ERROR; } } printf("Calling Creating javaVM\n"); if (JNI_CreateJavaVM(&(*p_vm), &(*p_env), &args)) { printf("JNI_CreateJavaVM failed\n"); return ERROR; } printf("Calling registerNatives\n"); if (registerNatives(*p_env, 0)) { printf("registerNatives failed\n"); return ERROR; } return 0; } int main(void) { int status = 0; char buffer[1024] = {0}; jclass echo_class; jobject echo_instance; jmethodID constructor_method; jstring result, buf_str; JavaVM *vm = NULL; JNIEnv *env = NULL; status = init_jvm(&vm, &env); if (0 != status) { printf("Initialization failure (%i)\n", status); return ERROR; } printf("Initialization success (vm=%p, env=%p)\n", vm, env); JniInvocationDestroy = dlsym(libandroid_runtime_dso, "JniInvocationDestroy"); if (!JniInvocationDestroy) { return ERROR; } printf("[+] Finding EchoUtils class\n"); echo_class = (*env)->FindClass(env, "com.alephsecurity.jniexample.EchoUtils"); if (NULL == echo_class) { printf("[!] Couldn't find EchoUtils on the class path\n"); return ERROR; } printf("[+] Found EchoUtils class: %p\n", echo_class); constructor_method = (*env)->GetMethodID(env, echo_class, "<init>", "()V"); if (NULL == constructor_method) { printf("[!] Could not find <init> method\n"); return ERROR; } printf("[+] Found <init>: %p\n", constructor_method); echo_instance = (*env)->NewObject(env, echo_class, constructor_method); if (NULL == echo_instance) { printf("[!] Couldn't call <init>\n"); if((*(env))->ExceptionCheck(env)) { printf("Exception occured!"); (*(env))->ExceptionDescribe(env); (*(env))->ExceptionClear(env); } return ERROR; } printf("[+] Instantiated EchoUtils class: %p\n", echo_instance); read(STDIN_FILENO, buffer, 1024); printf("stdin buffer: %s\n", buffer); buf_str = (*env)->NewStringUTF(env, buffer); printf("calling sendString\n"); result = Java_com_alephsecurity_jniexample_EchoUtils_sendString(env, echo_instance, buf_str); printf("Got result: %p\n", result); printf("The result is: %s\n", (*env)->GetStringUTFChars(env, result, NULL)); printf("[+] Cleaning up VM\n"); // When fuzzing with fork server don't destroy the JVM /** (*vm)->DestroyJavaVM(vm); printf("Calling JniInvocationDestroy\n"); JniInvocationDestroy(invocation); dlclose(libandroid_runtime_dso); **/ return 0; }
内容的提问来源于stack exchange,提问作者Boom
相关产品推荐
相关产品推荐

