afl-cmin.bash
Usage: ./afl-cmin.bash [ options ] -- /path/to/target_app [ ... ]
Required parameters:
-i dir - input directory with the starting corpus
-o dir - output directory for minimized files
Execution control settings:
-f file - location read by the fuzzed program (stdin)
-m megs - memory limit for child process (none MB)
-t msec - run time limit for child process (none)
-O - use binary-only instrumentation (FRIDA mode)
-Q - use binary-only instrumentation (QEMU mode)
-U - use unicorn-based instrumentation (Unicorn mode)
Minimization settings:
-A - allow crashing and timeout inputs
-C - keep crashing inputs, reject everything else
-e - solve for edge coverage only, ignore hit counts
For additional tips, please consult README.md.
Environment variables used:
AFL_KEEP_TRACES: leave the temporary <out_dir>.traces directory
AFL_NO_FORKSRV: run target via execve instead of using the forkserver
AFL_PATH: last resort location to find the afl-showmap binary
AFL_SKIP_BIN_CHECK: skip check for target binary
afl++ was written by Michal "lcamtuf" Zalewski and is maintained by
Marc "van Hauser" Heuse <
[email protected]>, Heiko
"hexcoder-" Eissfeldt <
[email protected]>, Andrea
Fioraldi <
[email protected]> and Dominik Maier
<
[email protected]> The homepage of afl++ is:
https://github.com/AFLplusplus/AFLplusplus
Apache License Version 2.0, January 2004