tree: 28884d44302839f906be912f68cca5f6111725e4 [path history] [tgz]
  1. read_into_rdi.c
  2. README.md
  3. test.c
examples/qemu_persistent_hook/README.md

QEMU persistent hook example

Compile the test binary and the library:

gcc -no-pie test.c -o test
gcc -fPIC -shared read_into_rdi.c -o read_into_rdi.so

Fuzz with:

export AFL_QEMU_PERSISTENT_ADDR=0x$(nm test | grep "T target_func" | awk '{print $1}')
export AFL_QEMU_PERSISTENT_HOOK=./read_into_rdi.so

mkdir in
echo 0000 > in/in

../../afl-fuzz -Q -i in -o out -- ./test