diff options
author | vanhauser-thc <vh@thc.org> | 2022-10-11 12:43:06 +0200 |
---|---|---|
committer | vanhauser-thc <vh@thc.org> | 2022-10-11 12:43:06 +0200 |
commit | de9d1ff4a09a72c8bd4bb892f146646296f3f2fa (patch) | |
tree | ce4fe27147f68d687fe8d995e6f2ce829a7417b8 /qemu_mode/README.persistent.md | |
parent | e6e82948bf95fab90466cb2dfa78457c4d2d80a6 (diff) | |
download | afl++-de9d1ff4a09a72c8bd4bb892f146646296f3f2fa.tar.gz |
doc fixes
Diffstat (limited to 'qemu_mode/README.persistent.md')
-rw-r--r-- | qemu_mode/README.persistent.md | 11 |
1 files changed, 6 insertions, 5 deletions
diff --git a/qemu_mode/README.persistent.md b/qemu_mode/README.persistent.md index ab45860d..ef8fb71b 100644 --- a/qemu_mode/README.persistent.md +++ b/qemu_mode/README.persistent.md @@ -27,11 +27,12 @@ function and will patch the return address (on stack or in the link register) to return to START (like WinAFL). *Note:* If the target is compiled with position independent code (PIE/PIC) qemu -loads these to a specific base address. For 64 bit you have to add 0x4000000000 -(9 zeroes) and for 32 bit 0x40000000 (7 zeroes) to the address. On strange -setups the base address set by QEMU for PIE executable may change. You can check -it printing the process map using `AFL_QEMU_DEBUG_MAPS=1 afl-qemu-trace -TARGET-BINARY`. +loads these to a specific base address. For amd64 bit you have to add +0x4000000000 (9 zeroes) and for 32 bit 0x40000000 (7 zeroes) to the address. +For aarch64 it is usually 0x5500000000. +On strange setups the base address set by QEMU for PIE executable may change. +You can check it printing the process map using +`AFL_QEMU_DEBUG_MAPS=1 afl-qemu-trace TARGET-BINARY`. If this address is not valid, afl-fuzz will error during startup with the message that the forkserver was not found. |