about summary refs log tree commit diff
path: root/examples/qemu_persistent_hook/README.md
diff options
context:
space:
mode:
authorAndrea Fioraldi <andreafioraldi@gmail.com>2020-02-07 20:43:17 +0100
committerAndrea Fioraldi <andreafioraldi@gmail.com>2020-02-07 20:43:17 +0100
commitf2f6be5e999632b05ce92b4934ee97531d546a44 (patch)
treec7eeea121fc83b5d0cf76daf59c47634c11bf264 /examples/qemu_persistent_hook/README.md
parentfd8fe4dd088464230df2dc456c5a9fbf905c907f (diff)
downloadafl++-f2f6be5e999632b05ce92b4934ee97531d546a44.tar.gz
afl qemu persistent hook
Diffstat (limited to 'examples/qemu_persistent_hook/README.md')
-rw-r--r--examples/qemu_persistent_hook/README.md20
1 files changed, 20 insertions, 0 deletions
diff --git a/examples/qemu_persistent_hook/README.md b/examples/qemu_persistent_hook/README.md
new file mode 100644
index 00000000..3278b60c
--- /dev/null
+++ b/examples/qemu_persistent_hook/README.md
@@ -0,0 +1,20 @@
+# QEMU persistent hook example
+
+Compile the test binary and the library:
+
+```
+gcc -no-pie test.c -o test
+gcc -fPIC -shared read_into_rdi.c -o read_into_rdi.so
+```
+
+Fuzz with:
+
+```
+export AFL_QEMU_PERSISTENT_ADDR=0x$(nm test | grep "T target_func" | awk '{print $1}')
+export AFL_QEMU_PERSISTENT_HOOK=./read_into_rdi.so
+
+mkdir in
+echo 0000 > in/in
+
+../../afl-fuzz -Q -i in -o out -- ./test
+```