Master the fundamental concepts of binary exploitation through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksFuzzing feeds random, malformed, or unexpected inputs to a program to find crashes and security vulnerabilities. Coverage-guided fuzzing uses code coverage feedback to prioritize inputs that explore new program paths.
libFuzzer is an in-process coverage-guided fuzzer from LLVM:
The fuzz target signature:
cLoading…
For example, a parser bug triggered by input \x00\xFF\x42 will be saved as a crashing test case for triage.
You will instrument a buggy parser exactly the way libFuzzer would: feed it one fuzz input given as a hex string, count how many of its checks the input passes (the coverage signal), and report the first crash the parser reaches: the unchecked length byte overflowing buffer[16], or the divide-by-zero behind it. The crash hash you compute for the saved crashing input mirrors the corpus file libFuzzer writes for triage.
Seed your corpus with valid inputs: protocol headers, file format magic bytes, and minimal valid documents. libFuzzer mutates by flipping bits, inserting bytes, and splicing inputs together. Inputs that reach new code paths are saved to the corpus for future mutations. OSS-Fuzz runs libFuzzer continuously against open-source projects, finding thousands of security bugs before they reach production releases.
Write a C program that acts as the fuzz target instrumentation: it parses one input (given as a hex string on stdin) against a buggy parser and reports coverage and crash class.
The parser under test accepts 4-byte magic "FUZZ", reads byte 4 as an unchecked length, copies that many payload bytes into buffer[16], then divides a checksum by data[5].
Requirements:
Success Criteria: