1
0

fuzzIBSS.c 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. /*
  2. Fuzzes ibss Information element
  3. */
  4. #include <stdio.h>
  5. #include <stdlib.h>
  6. #include <stdint.h>
  7. #include <string.h>
  8. #include "../frameDefinitions.h"
  9. //Indecates whether the ibssFuzzer is running
  10. int ibssRunningState = 0;
  11. //Number of fuzzing states
  12. const int ibssStates = 4;
  13. //Steps of fuzzers for each fuzzing state
  14. const int ibssSteps[] = {1, 2, 16, 16};
  15. //Current state and step of the ibssFuzzer
  16. int fuzzState;
  17. int fuzzStep;
  18. void ibssPrintCurrentState()
  19. {
  20. switch (fuzzState)
  21. {
  22. case 0:
  23. {
  24. printf("\e[33mFuzzing ibss IE\e[39m\n");
  25. printf("Trying 255*0xFF data\n");
  26. break;
  27. }
  28. case 1:
  29. {
  30. printf("Fuzzing ATIM Window\n");
  31. break;
  32. }
  33. case 2:
  34. {
  35. printf("Fuzzing lengths with 0xFF data\n");
  36. break;
  37. }
  38. case 3:
  39. {
  40. printf("Fuzzing lengths with 0x00 data\n");
  41. break;
  42. }
  43. case 4:
  44. {
  45. printf("\e[33mDone with fuzzing ibss\e[39m\n");
  46. break;
  47. }
  48. }
  49. }
  50. //Updates ibssFuzzer
  51. //Status 0 indicates start
  52. //Status 1 indicates increaseStep
  53. //Status 2 indicates stop
  54. //Returns -1 if done with fuzzing
  55. int ibssFuzzUpdate(int status)
  56. {
  57. switch (status)
  58. {
  59. case 0: //start fuzzer
  60. {
  61. ibssRunningState = 1;
  62. fuzzState = 0;
  63. fuzzStep = 0;
  64. ibssPrintCurrentState();
  65. break;
  66. }
  67. case 1: //update fuzzer
  68. {
  69. if (ibssRunningState == 1) //sanity check
  70. {
  71. //increase steps until all steps are done
  72. if (fuzzStep < ibssSteps[fuzzState]-1)
  73. fuzzStep = fuzzStep + 1;
  74. //then increase state and notify
  75. else
  76. {
  77. fuzzStep = 0;
  78. fuzzState = fuzzState + 1;
  79. ibssPrintCurrentState();
  80. }
  81. //when all states are done, stop
  82. if (fuzzState == ibssStates)
  83. {
  84. ibssRunningState = 0;
  85. return -1;
  86. }
  87. }
  88. break;
  89. }
  90. case 2: //stop fuzzer
  91. {
  92. ibssRunningState = 0;
  93. break;
  94. }
  95. }
  96. return 0;
  97. }
  98. //Returns an ibss information element
  99. infoElem ibssFuzz()
  100. {
  101. infoElem ibss;
  102. //What to return when not fuzzed
  103. if (ibssRunningState == 0)
  104. {
  105. ibss.id = 0;
  106. ibss.len = 1;
  107. ibss.len_data = -1;
  108. ibss.data = "\xab";
  109. }
  110. else
  111. {
  112. switch (fuzzState) //update this
  113. {
  114. case 0: //255*0xff
  115. {
  116. ibss.id = 6;
  117. ibss.len = 255;
  118. ibss.len_data = 255;
  119. //create data of 255 times 0xff
  120. u_char *data = malloc(255);
  121. memset(data, 0xff, 255);
  122. ibss.data = data;
  123. break;
  124. }
  125. case 1: //ibss null data
  126. {
  127. if (fuzzStep == 0)
  128. {
  129. ibss.id = 6;
  130. ibss.len = 2;
  131. ibss.len_data = 2;
  132. ibss.data = "\x00\x00";
  133. }
  134. else
  135. {
  136. ibss.id = 6;
  137. ibss.len = 2;
  138. ibss.len_data = 2;
  139. ibss.data = "\xFF\xFF";
  140. }
  141. break;
  142. }
  143. case 2: //length with 0xff data
  144. {
  145. if (fuzzStep < 8)
  146. {
  147. int dataSize = fuzzStep;
  148. ibss.id = 6;
  149. ibss.len = dataSize;
  150. ibss.len_data = dataSize;
  151. //create data of datasize times 0xff
  152. u_char *data = malloc(dataSize);
  153. memset(data, 0xff, dataSize);
  154. ibss.data = data;
  155. }
  156. else
  157. {
  158. int dataSize = 255 - fuzzStep + 8;
  159. ibss.id = 6;
  160. ibss.len = dataSize;
  161. ibss.len_data = dataSize;
  162. //create data of datasize times 0xff
  163. u_char *data = malloc(dataSize);
  164. memset(data, 0xff, dataSize);
  165. ibss.data = data;
  166. }
  167. break;
  168. }
  169. case 3: //length with 0x00 data
  170. {
  171. if (fuzzStep < 8)
  172. {
  173. int dataSize = fuzzStep;
  174. ibss.id = 6;
  175. ibss.len = dataSize;
  176. ibss.len_data = dataSize;
  177. //create data of datasize times 0x00
  178. u_char *data = malloc(dataSize);
  179. memset(data, 0x00, dataSize);
  180. ibss.data = data;
  181. }
  182. else
  183. {
  184. int dataSize = 255 - fuzzStep + 8;
  185. ibss.id = 6;
  186. ibss.len = dataSize;
  187. ibss.len_data = dataSize;
  188. //create data of datasize times 0x00
  189. u_char *data = malloc(dataSize);
  190. memset(data, 0x00, dataSize);
  191. ibss.data = data;
  192. }
  193. break;
  194. }
  195. }
  196. }
  197. return ibss;
  198. }