Add text boxes to Fuzzing window to make it easy to set the bytes

directly and to show feedback while fuzzing is running.
This commit is contained in:
Collin Kidder
2020-02-15 21:25:32 -05:00
parent e4a3854af4
commit 909710fcfa
9 changed files with 207 additions and 13 deletions
Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB

After

Width:  |  Height:  |  Size: 65 KiB

+3 -2
View File
@@ -9,7 +9,7 @@
* Released under the MIT license
* https://jquery.org/license
*
* Date: 2019-01-30T03:06Z
* Date: 2019-04-19T06:52Z
*/
( function( global, factory ) {
@@ -261,8 +261,9 @@ jQuery.extend = jQuery.fn.extend = function() {
src = target[ name ];
copy = options[ name ];
// Prevent Object.prototype pollution
// Prevent never-ending loop
if ( target === copy ) {
if ( name === "__proto__" || target === copy ) {
continue;
}
+6 -4
View File
@@ -25,11 +25,12 @@
</div>
<div class="section" id="fuzzing-is-dangerous">
<h1>60. Fuzzing is Dangerous</h1>
<p>You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you’re right there and you can stop it. Even better, don’t do it unless your car is up on a hoist or something and can’t drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car.</p>
<p>You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you’re right there and you can stop it. Even better, don’t do it unless your car is up on a hoist or jacks and can’t drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car. If you break something you own the pieces.</p>
</div>
<div class="section" id="controlling-the-fuzzy-beast">
<h1>61. Controlling the Fuzzy Beast</h1>
<p>So, you want to give it a try? Let’s do it! First of all, you can set the delay between frames and the burst rate. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That’s all the simple settings. It gets a bit more complicated now.</p>
<p>So, you want to give it a try? Let’s do it! First of all, you can set the delay between frames and the burst rate. The delay is in milliseconds but can be set as low as 0. If the delay is set to 0 then the system will attempt to send frames as fast as it can. However, even then you may not get quite as many frames per second as you’d like. Even at 0 it will still be scheduled by your operating system and so might not quite get to the speed you want. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. If you need rapid frame sending your best bet is to set the sending interval to 1-2ms and then adjust the burst
rate until you get your desired sending rate. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That’s all the simple settings. It gets a bit more complicated now.</p>
<p>The “ID Scanning” box has two radio buttons:</p>
<ol class="arabic simple">
<li>Sequential will go from “Start ID” to “End ID” then reset back to Start over and over.</li>
@@ -46,11 +47,12 @@
<li>Sweep causes the system to set the first one, then unset that one and set the second bit, then unset that, etc. Thus the fuzzed bit sweeps and only one fuzzed bit is set at once.</li>
<li>Random will randomly pick whether each fuzzed bit is set or not.</li>
</ol>
<p>In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in “Bit Scanning”</p>
<p>In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in “Bit Scanning” You can also set the bytes directly with the text boxes above the 8x8 grid. Setting a hexadecimal value in these
boxes will set the relavent bits in the 8x8 grid. You must press the ENTER/RETURN key to set the values. Merely changing the value will not update it (as a safety measure).</p>
</div>
<div class="section" id="pulling-the-trigger">
<h1>62. Pulling the Trigger</h1>
<p>Once you’ve configured everything click “Start Fuzzing” to give it a shot. You will see the number of frames sent so far listed below the button. You can stop the fuzzing by pushing the button again.</p>
<p>Once you’ve configured everything click “Start Fuzzing” to give it a shot. You will see the number of frames sent so far listed below the button. Approximately four times per second the current value for each byte is copied into the text boxes just above the 8x8 grid. This can be used to see what is going on and to ensure that it is working the way you want it to. You can stop the fuzzing by pushing the start button again.</p>
</div>