Add text boxes to Fuzzing window to make it easy to set the bytes
directly and to show feedback while fuzzing is running.
This commit is contained in:
@@ -119,8 +119,6 @@ bool SerialBusConnection::piSendFrame(const CANFrame& pFrame)
|
||||
return false;
|
||||
if (!mDev_p) return false;
|
||||
|
||||
qDebug() << "Data bytes at lowlevel: " << pFrame.payload().toBase64();
|
||||
|
||||
return mDev_p->writeFrame(pFrame);
|
||||
}
|
||||
|
||||
|
||||
@@ -13,12 +13,13 @@ Some people are big fans of fuzzing, some people have no use for it. There usual
|
||||
|
||||
Fuzzing is Dangerous
|
||||
====================
|
||||
You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you're right there and you can stop it. Even better, don't do it unless your car is up on a hoist or something and can't drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car.
|
||||
You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you're right there and you can stop it. Even better, don't do it unless your car is up on a hoist or jacks and can't drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car. If you break something you own the pieces.
|
||||
|
||||
Controlling the Fuzzy Beast
|
||||
===========================
|
||||
|
||||
So, you want to give it a try? Let's do it! First of all, you can set the delay between frames and the burst rate. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That's all the simple settings. It gets a bit more complicated now.
|
||||
So, you want to give it a try? Let's do it! First of all, you can set the delay between frames and the burst rate. The delay is in milliseconds but can be set as low as 0. If the delay is set to 0 then the system will attempt to send frames as fast as it can. However, even then you may not get quite as many frames per second as you'd like. Even at 0 it will still be scheduled by your operating system and so might not quite get to the speed you want. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. If you need rapid frame sending your best bet is to set the sending interval to 1-2ms and then adjust the burst
|
||||
rate until you get your desired sending rate. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That's all the simple settings. It gets a bit more complicated now.
|
||||
|
||||
The "ID Scanning" box has two radio buttons:
|
||||
|
||||
@@ -36,9 +37,10 @@ The last box is "Bit Scanning"
|
||||
2. Sweep causes the system to set the first one, then unset that one and set the second bit, then unset that, etc. Thus the fuzzed bit sweeps and only one fuzzed bit is set at once.
|
||||
3. Random will randomly pick whether each fuzzed bit is set or not.
|
||||
|
||||
In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in "Bit Scanning"
|
||||
In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in "Bit Scanning" You can also set the bytes directly with the text boxes above the 8x8 grid. Setting a hexadecimal value in these
|
||||
boxes will set the relavent bits in the 8x8 grid. You must press the ENTER/RETURN key to set the values. Merely changing the value will not update it (as a safety measure).
|
||||
|
||||
Pulling the Trigger
|
||||
===================
|
||||
|
||||
Once you've configured everything click "Start Fuzzing" to give it a shot. You will see the number of frames sent so far listed below the button. You can stop the fuzzing by pushing the button again.
|
||||
Once you've configured everything click "Start Fuzzing" to give it a shot. You will see the number of frames sent so far listed below the button. Approximately four times per second the current value for each byte is copied into the text boxes just above the 8x8 grid. This can be used to see what is going on and to ensure that it is working the way you want it to. You can stop the fuzzing by pushing the start button again.
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 73 KiB After Width: | Height: | Size: 65 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 73 KiB After Width: | Height: | Size: 65 KiB |
Vendored
+3
-2
@@ -9,7 +9,7 @@
|
||||
* Released under the MIT license
|
||||
* https://jquery.org/license
|
||||
*
|
||||
* Date: 2019-01-30T03:06Z
|
||||
* Date: 2019-04-19T06:52Z
|
||||
*/
|
||||
( function( global, factory ) {
|
||||
|
||||
@@ -261,8 +261,9 @@ jQuery.extend = jQuery.fn.extend = function() {
|
||||
src = target[ name ];
|
||||
copy = options[ name ];
|
||||
|
||||
// Prevent Object.prototype pollution
|
||||
// Prevent never-ending loop
|
||||
if ( target === copy ) {
|
||||
if ( name === "__proto__" || target === copy ) {
|
||||
continue;
|
||||
}
|
||||
|
||||
|
||||
@@ -25,11 +25,12 @@
|
||||
</div>
|
||||
<div class="section" id="fuzzing-is-dangerous">
|
||||
<h1>60. Fuzzing is Dangerous</h1>
|
||||
<p>You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you’re right there and you can stop it. Even better, don’t do it unless your car is up on a hoist or something and can’t drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car.</p>
|
||||
<p>You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you’re right there and you can stop it. Even better, don’t do it unless your car is up on a hoist or jacks and can’t drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car. If you break something you own the pieces.</p>
|
||||
</div>
|
||||
<div class="section" id="controlling-the-fuzzy-beast">
|
||||
<h1>61. Controlling the Fuzzy Beast</h1>
|
||||
<p>So, you want to give it a try? Let’s do it! First of all, you can set the delay between frames and the burst rate. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That’s all the simple settings. It gets a bit more complicated now.</p>
|
||||
<p>So, you want to give it a try? Let’s do it! First of all, you can set the delay between frames and the burst rate. The delay is in milliseconds but can be set as low as 0. If the delay is set to 0 then the system will attempt to send frames as fast as it can. However, even then you may not get quite as many frames per second as you’d like. Even at 0 it will still be scheduled by your operating system and so might not quite get to the speed you want. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. If you need rapid frame sending your best bet is to set the sending interval to 1-2ms and then adjust the burst
|
||||
rate until you get your desired sending rate. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That’s all the simple settings. It gets a bit more complicated now.</p>
|
||||
<p>The “ID Scanning” box has two radio buttons:</p>
|
||||
<ol class="arabic simple">
|
||||
<li>Sequential will go from “Start ID” to “End ID” then reset back to Start over and over.</li>
|
||||
@@ -46,11 +47,12 @@
|
||||
<li>Sweep causes the system to set the first one, then unset that one and set the second bit, then unset that, etc. Thus the fuzzed bit sweeps and only one fuzzed bit is set at once.</li>
|
||||
<li>Random will randomly pick whether each fuzzed bit is set or not.</li>
|
||||
</ol>
|
||||
<p>In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in “Bit Scanning”</p>
|
||||
<p>In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in “Bit Scanning” You can also set the bytes directly with the text boxes above the 8x8 grid. Setting a hexadecimal value in these
|
||||
boxes will set the relavent bits in the 8x8 grid. You must press the ENTER/RETURN key to set the values. Merely changing the value will not update it (as a safety measure).</p>
|
||||
</div>
|
||||
<div class="section" id="pulling-the-trigger">
|
||||
<h1>62. Pulling the Trigger</h1>
|
||||
<p>Once you’ve configured everything click “Start Fuzzing” to give it a shot. You will see the number of frames sent so far listed below the button. You can stop the fuzzing by pushing the button again.</p>
|
||||
<p>Once you’ve configured everything click “Start Fuzzing” to give it a shot. You will see the number of frames sent so far listed below the button. Approximately four times per second the current value for each byte is copied into the text boxes just above the 8x8 grid. This can be used to see what is going on and to ensure that it is working the way you want it to. You can stop the fuzzing by pushing the start button again.</p>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
@@ -26,6 +26,15 @@ FuzzingWindow::FuzzingWindow(const QVector<CANFrame> *frames, QWidget *parent) :
|
||||
connect(ui->listID, &QListWidget::itemChanged, this, &FuzzingWindow::idListChanged);
|
||||
connect(ui->spinBytes, SIGNAL(valueChanged(int)), this, SLOT(changedNumDataBytes(int)));
|
||||
connect(ui->bitfield, SIGNAL(gridClicked(int,int)), this, SLOT(bitfieldClicked(int,int)));
|
||||
connect(ui->txtByte0, &QLineEdit::returnPressed, this, [=](){changedDataByteText(0, ui->txtByte0->text());});
|
||||
connect(ui->txtByte1, &QLineEdit::returnPressed, this, [=](){changedDataByteText(1, ui->txtByte1->text());});
|
||||
connect(ui->txtByte2, &QLineEdit::returnPressed, this, [=](){changedDataByteText(2, ui->txtByte2->text());});
|
||||
connect(ui->txtByte3, &QLineEdit::returnPressed, this, [=](){changedDataByteText(3, ui->txtByte3->text());});
|
||||
connect(ui->txtByte4, &QLineEdit::returnPressed, this, [=](){changedDataByteText(4, ui->txtByte4->text());});
|
||||
connect(ui->txtByte5, &QLineEdit::returnPressed, this, [=](){changedDataByteText(5, ui->txtByte5->text());});
|
||||
connect(ui->txtByte6, &QLineEdit::returnPressed, this, [=](){changedDataByteText(6, ui->txtByte6->text());});
|
||||
connect(ui->txtByte7, &QLineEdit::returnPressed, this, [=](){changedDataByteText(7, ui->txtByte7->text());});
|
||||
|
||||
|
||||
connect(MainWindow::getReference(), SIGNAL(framesUpdated(int)), this, SLOT(updatedFrames(int)));
|
||||
|
||||
@@ -110,9 +119,32 @@ void FuzzingWindow::changePlaybackSpeed(int newSpeed)
|
||||
fuzzTimer->setInterval(newSpeed);
|
||||
}
|
||||
|
||||
void FuzzingWindow::changedDataByteText(int which, QString valu)
|
||||
{
|
||||
int startBit = which * 8;
|
||||
int byt = valu.toInt(nullptr, 16);
|
||||
|
||||
for (int i = 0; i < 8; i++)
|
||||
{
|
||||
bitGrid[startBit + i] = (byt & (1 << i)) ? 2 : 0;
|
||||
}
|
||||
|
||||
redrawGrid();
|
||||
}
|
||||
|
||||
void FuzzingWindow::changedNumDataBytes(int newVal)
|
||||
{
|
||||
qDebug() << "new num bytes: " << newVal;
|
||||
|
||||
ui->txtByte0->setEnabled((newVal > 0) ? true : false);
|
||||
ui->txtByte1->setEnabled((newVal > 1) ? true : false);
|
||||
ui->txtByte2->setEnabled((newVal > 2) ? true : false);
|
||||
ui->txtByte3->setEnabled((newVal > 3) ? true : false);
|
||||
ui->txtByte4->setEnabled((newVal > 4) ? true : false);
|
||||
ui->txtByte5->setEnabled((newVal > 5) ? true : false);
|
||||
ui->txtByte6->setEnabled((newVal > 6) ? true : false);
|
||||
ui->txtByte7->setEnabled((newVal > 7) ? true : false);
|
||||
|
||||
int byt;
|
||||
for (int i = 0; i < 64; i++)
|
||||
{
|
||||
@@ -132,8 +164,21 @@ void FuzzingWindow::changedNumDataBytes(int newVal)
|
||||
|
||||
void FuzzingWindow::timerTriggered()
|
||||
{
|
||||
static uint64_t lastByteUpdate = 0;
|
||||
CANFrame thisFrame;
|
||||
sendingBuffer.clear();
|
||||
//Every 250ms update the text fields to show our progress and what's going on.
|
||||
if (QDateTime::currentMSecsSinceEpoch() - lastByteUpdate > 250)
|
||||
{
|
||||
ui->txtByte0->setText(QString::number(currentBytes[0], 16));
|
||||
ui->txtByte1->setText(QString::number(currentBytes[1], 16));
|
||||
ui->txtByte2->setText(QString::number(currentBytes[2], 16));
|
||||
ui->txtByte3->setText(QString::number(currentBytes[3], 16));
|
||||
ui->txtByte4->setText(QString::number(currentBytes[4], 16));
|
||||
ui->txtByte5->setText(QString::number(currentBytes[5], 16));
|
||||
ui->txtByte6->setText(QString::number(currentBytes[6], 16));
|
||||
ui->txtByte7->setText(QString::number(currentBytes[7], 16));
|
||||
}
|
||||
int buses = ui->cbBuses->currentIndex();
|
||||
for (int count = 0; count < ui->spinBurst->value(); count++)
|
||||
{
|
||||
|
||||
@@ -65,6 +65,7 @@ private:
|
||||
void calcNextBitPattern();
|
||||
void redrawGrid();
|
||||
bool eventFilter(QObject *obj, QEvent *event);
|
||||
void changedDataByteText(int which, QString valu);
|
||||
};
|
||||
|
||||
#endif // FUZZINGWINDOW_H
|
||||
|
||||
+146
-1
@@ -13,7 +13,7 @@
|
||||
<property name="windowTitle">
|
||||
<string>Fuzzing Window</string>
|
||||
</property>
|
||||
<layout class="QVBoxLayout" name="verticalLayout" stretch="1,1,3,6,0,0,0">
|
||||
<layout class="QVBoxLayout" name="verticalLayout" stretch="1,1,3,0,0,6,0,0,0">
|
||||
<item>
|
||||
<layout class="QHBoxLayout" name="horizontalLayout">
|
||||
<item>
|
||||
@@ -248,6 +248,151 @@
|
||||
</item>
|
||||
</layout>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_8">
|
||||
<property name="text">
|
||||
<string>Byte Values (Always in hexadecimal)</string>
|
||||
</property>
|
||||
<property name="alignment">
|
||||
<set>Qt::AlignCenter</set>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<layout class="QHBoxLayout" name="horizontalLayout_10">
|
||||
<item>
|
||||
<widget class="QLabel" name="label_9">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>0</string>
|
||||
</property>
|
||||
<property name="textFormat">
|
||||
<enum>Qt::PlainText</enum>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte0"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_10">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>1</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte1"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_11">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>2</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte2"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_12">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>3</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte3"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_13">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>4</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte4"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_14">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>5</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte5"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_15">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>6</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte6"/>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLabel" name="label_16">
|
||||
<property name="font">
|
||||
<font>
|
||||
<weight>75</weight>
|
||||
<bold>true</bold>
|
||||
</font>
|
||||
</property>
|
||||
<property name="text">
|
||||
<string>7</string>
|
||||
</property>
|
||||
</widget>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="QLineEdit" name="txtByte7"/>
|
||||
</item>
|
||||
</layout>
|
||||
</item>
|
||||
<item>
|
||||
<widget class="CANDataGrid" name="bitfield" native="true">
|
||||
<property name="minimumSize">
|
||||
|
||||
Reference in New Issue
Block a user