Update tracing.md

This commit is contained in:
pdamian
2023-11-28 08:46:42 +01:00
committed by GitHub
parent 451d8196ca
commit f42f834e88
+31 -5
View File
@@ -1,9 +1,14 @@
# Table of Contents
1. [Tracing](./tracing.md)
1. [Hooks](./tracing.md#Hooks)
2. [States](./tracing.md#states)
1. [Emulation](./emulation.md)
2. [Tracing](./tracing.md)
1. [Setup](./tracing.md#setup)
1. [Hooks](./tracing.md#hooks)
2. [States](./tracing.md#states)
2. [Run](./tracing.md#run)
4. [Symbolic Execution](./symbex.md)
# Tracing
## Hooks
## Setup
### Hooks
[circled.init.yaml](../morion/circled.init.yaml):
```
hooks:
@@ -20,7 +25,7 @@ hooks:
- {entry: '0xcffc', leave: '0xd000', mode: 'model'} # sscanf@plt
[...]
```
## States
### States
[circled.init.yaml](../morion/circled.init.yaml):
```
[...]
@@ -35,3 +40,24 @@ states:
'0x000120fd': ['0x00'] #
[...]
```
## Run
Use the following steps to create a **trace** of the binary _circled_, while it is targeted with a _proof-of-vulnerability (PoV)_ payload (as for instance being identified by a fuzzer):
1. Start a HTTP server, delivering PoV payloads:
- System: [Guest](./setup.md)
- Command:
```
python3 server/circled.server.py --payload "pov"
```
2. Emulate the binary _circled_ with GDB attached (and therefore not using ASRL):
- System: [Guest (chroot)](./setup.md)
- Command:
```
/circled.sh --gdb
3. Collect an execution trace of the binary _circled_:
- System: [Host (morion)](./setup.md)
- Command:
```
cd morion/; # Ensure to be within the correct directory
cp circled.init.yaml circled.yaml; # Start with a fresh circled.yaml file
gdb-multiarch -q -x circled.trace.gdb; # Use GDB for cross-platform remote trace collection
```