Closed DerZc closed 2 years ago
You can. In the configuration file, add a section like this [libname] * = fname(conditions on parameters to taint the result)
For instance to add a rule for memcpy: [.dynsym] * = memcpy(_, , )
will taint the return value if either the second or the third argument is tainted
You can also override the taint and/or value of any register at any instruction [overrride] instruction address = reg[rname], mask | mem[address], mask
with
Hi! I have another question. Can I taint a function that set the return value of this funtion as taint.