Current Version: 2.52b
More Versions: LLVM 4.0 (build from souce to have Gold Plugin)
Last Update: 2019/08
Type: AFL-based
Tag: directed fuzzing
Here is an example of using AFLGo: . And we provide pre-built image aflgo_example_lrzip.
# apt install -y subversion
svn export seed_lrz
mkdir -p output/aflgo
docker run --rm -w /work -it -v `pwd`:/work --privileged zjuchenyuan/aflgo_example_lrzip \
/aflgo/afl-fuzz -m none -z exp -c 45m -i seed_lrz -o output/aflgo -- \
/lrzip-CVE-2018-11496/obj-aflgo/lrzip -t @@
FROM zjuchenyuan/base
RUN apt update && \
apt install -y sudo curl wget build-essential make cmake ninja-build git subversion python2.7 binutils-gold binutils-dev python-dev python3 python3-dev python3-pip autoconf automake libtool-bin python-bs4 libclang-4.0-dev gawk pkg-config &&\
python3 -m pip install --upgrade pip && python3 -m pip install networkx pydot pydotplus
RUN mkdir -p /build && cd /build &&\
wget &&\
tar xf llvm-4.0.0.src.tar.xz && tar xf cfe-4.0.0.src.tar.xz && tar xf compiler-rt-4.0.0.src.tar.xz && tar xf libcxx-4.0.0.src.tar.xz && tar xf libcxxabi-4.0.0.src.tar.xz &&\
rm *.tar.xz &&\
mv cfe-4.0.0.src /build/llvm-4.0.0.src/tools/clang && mv compiler-rt-4.0.0.src /build/llvm-4.0.0.src/projects/compiler-rt && mv libcxx-4.0.0.src /build/llvm-4.0.0.src/projects/libcxx && mv libcxxabi-4.0.0.src /build/llvm-4.0.0.src/projects/libcxxabi &&\
mkdir -p build-llvm/llvm; cd build-llvm/llvm &&\
cmake -G "Ninja" \
-DLLVM_BINUTILS_INCDIR=/usr/include /build/llvm-4.0.0.src &&\
ninja && ninja install &&\
mkdir /usr/lib/bfd-plugins && \
cp /usr/local/lib/ /usr/lib/bfd-plugins &&\
cp /usr/local/lib/ /usr/lib/bfd-plugins
RUN mkdir -p /build/build-llvm/msan && cd /build/build-llvm/msan &&\
cmake -G "Ninja" \
/build/llvm-4.0.0.src &&\
ninja cxx && ninja install-cxx
RUN git clone &&\
cd aflgo && make all &&\
cd /aflgo/llvm_mode && make all
ENV AFLGO /aflgo
Since DockerHub auto-build cannot build LLVM in 4 hours (maxinum time allowed for building Docker images), I locally built and pushed the image.
I investigated many methods to skip the building process, but in vain: aflgo/aflgo#51
Can you help building aflgo without building LLVM? Please also build this image to verify your built aflgo can build target program.
CCS 2017: Directed Greybox Fuzzing PDF