Files in the top-level directory from the latest check-in
- .fossil-settings
- cwe369
- cwe476
- generic
- COPYING
- cover.c
- e9cd
- fix.m4
- helpers.cc
- helpers.hh
- helpers.m4
- jump.c
- Makefile
- measure-stack.cc
- no-crash.m4
- README.md
- scout.cc
- sort-inputs.m4
- trace-call.cc
Taosc
Taosc is an automated makeshift patcher for binary programs.
Installation
Taosc depends on AFL++, Dyninst, E9Patch, GNU Findutils, FUZZOLIC
and POSIX utilities. To build and install taosct to $prefix
(default to /usr/local), you need GNU M4, install(1p)
and a compiler for C++23 and Zig 0.15:
make -j$(nproc) PREFIX=$prefix install
Usage
taosc-fix TIMEOUT WORKDIR PROOFS_OF_CONCEPT EXECUTABLE ARG...
Fix EXECUTABLE, which crashes for PoC(s) in the PROOFS_OF_CONCEPT directory
when it is run with ARG(s), where @@ is the placeholder for input files.
Processes taking more than TIMEOUT seconds to terminate
are treated the same as crashes.
Files in WORKDIR are overwritten without any warning.
A successful invocation of taosc should create the following files.
patch-location: address of the patch locationpredicates: newline-separated list of patch predicates, to be set as the environment variableTAOSC_PREDdestinations: newline-separated list of jump destionations, to be set as the environment variableTAOSC_DESTPROG.patched, wherePROGis the basename ofEXECUTABLE: patched program expecting the mentioned environment variables
Currently the predicate format is being reworked and PROG.patched
cannot parse the ones in predicates. Please see patch.c
for its predicate parsing logic.
Copying
Taosc is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.