about summary refs log tree commit diff
diff options
context:
space:
mode:
-rw-r--r--README.md10
1 files changed, 9 insertions, 1 deletions
diff --git a/README.md b/README.md
index 23b71c8e..dbf54075 100644
--- a/README.md
+++ b/README.md
@@ -1,6 +1,12 @@
 # qemu_taint variant.
 
-CAVEATS:
+## HOWTO
+
+cd qemu_taint && ./build_qemu_taint.sh
+
+afl-fuzz -A ...
+
+## CAVEATS
 
  * shmem persistent mode does not work
  * custom mutators? dunno if they work or not
@@ -8,6 +14,8 @@ CAVEATS:
  * not tested with qemu_mode
  * if all seed entries are fully touched it might not work
 
+## THE TAINT
+
 taint can be seen in out/taint/
 
 the id:000 mirrors the out/queue entry, except the content it 0x00 for