Open DonggeLiu opened 5 years ago
Not quite sure if this the right way:
AFL_ROOT="/AFL/afl"
INPUT="/AFL/INPUTS"
OUTPUT="/AFL/OUTPUTS"
AFL_CMDLINE="/replace/replace.afl @@"
QSYM_CMDLINE="/replace/replace"
# run AFL master
$AFL_ROOT/afl-fuzz -M afl-master -i $INPUT -o $OUTPUT -- $AFL_CMDLINE &
# run AFL slave
$AFL_ROOT/afl-fuzz -S afl-slave -i $INPUT -o $OUTPUT -- $AFL_CMDLINE &
# run QSYM
bin/run_qsym_afl.py -a afl-slave -o $OUTPUT -n qsym -- $QSYM_CMDLINE
It did not give too many inputs, though.
We do have the docker of QSYM, but:
Tracer
, which is fromANGR
, I am not too sure if it's a fair comparison as they have multiple optimisations that we did not adopt.