220 lines
19 KiB
HTML
220 lines
19 KiB
HTML
|
||
<!DOCTYPE html>
|
||
|
||
<html>
|
||
<head>
|
||
<meta charset="utf-8" />
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||
<title>58. Fuzzing Window — SavvyCAN 189 documentation</title>
|
||
<link rel="stylesheet" href="_static/pygments.css" type="text/css" />
|
||
<link rel="stylesheet" href="_static/alabaster.css" type="text/css" />
|
||
<script id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script>
|
||
<script src="_static/jquery.js"></script>
|
||
<script src="_static/underscore.js"></script>
|
||
<script src="_static/doctools.js"></script>
|
||
<link rel="index" title="Index" href="genindex.html" />
|
||
<link rel="search" title="Search" href="search.html" />
|
||
<link rel="next" title="63. ISO-TP Decoder" href="isotp_decoder.html" />
|
||
<link rel="prev" title="55. File Comparison Window" href="filecomparison.html" />
|
||
|
||
<link rel="stylesheet" href="_static/custom.css" type="text/css" />
|
||
|
||
<meta name="viewport" content="width=device-width, initial-scale=0.9, maximum-scale=0.9" />
|
||
|
||
</head><body>
|
||
|
||
|
||
<div class="document">
|
||
<div class="documentwrapper">
|
||
<div class="bodywrapper">
|
||
<div class="body" role="main">
|
||
|
||
<div class="section" id="fuzzing-window">
|
||
<h1><span class="section-number">58. </span>Fuzzing Window<a class="headerlink" href="#fuzzing-window" title="Permalink to this headline">¶</a></h1>
|
||
<p>.</p>
|
||
<img alt="_images/FuzzingWindow.png" src="_images/FuzzingWindow.png" />
|
||
</div>
|
||
<div class="section" id="the-purpose-of-fuzzing">
|
||
<h1><span class="section-number">59. </span>The Purpose of Fuzzing<a class="headerlink" href="#the-purpose-of-fuzzing" title="Permalink to this headline">¶</a></h1>
|
||
<p>Some people are big fans of fuzzing, some people have no use for it. There usually isn’t much in between. So, what is fuzzing and why would you want to do it? Fuzzing is intentionally sending random information to see what happens. It’s pretty much the “shotgun” solution - you fire birdshot into the air and see if it hits anything. Does that sound a bit dangerous? It kind of is. So, why do it? It might help you to find frame IDs that control things. It might help you to find a data byte that controls something. Used carefully it can be used to figure out how different values affect things.</p>
|
||
</div>
|
||
<div class="section" id="fuzzing-is-dangerous">
|
||
<h1><span class="section-number">60. </span>Fuzzing is Dangerous<a class="headerlink" href="#fuzzing-is-dangerous" title="Permalink to this headline">¶</a></h1>
|
||
<p>You have now been warned. Sending random garbage over the CAN bus to see what happens could mess something up. It just might put your vehicle into gear and cause you to drive over a box full of kittens. Be careful! Never fuzz a car unless you’re right there and you can stop it. Even better, don’t do it unless your car is up on a hoist or jacks and can’t drive over anyone. Even still, there is a small chance you could cause an adverse effect to your car. If you break something you own the pieces.</p>
|
||
</div>
|
||
<div class="section" id="controlling-the-fuzzy-beast">
|
||
<h1><span class="section-number">61. </span>Controlling the Fuzzy Beast<a class="headerlink" href="#controlling-the-fuzzy-beast" title="Permalink to this headline">¶</a></h1>
|
||
<p>So, you want to give it a try? Let’s do it! First of all, you can set the delay between frames and the burst rate. The delay is in milliseconds but can be set as low as 0. If the delay is set to 0 then the system will attempt to send frames as fast as it can. However, even then you may not get quite as many frames per second as you’d like. Even at 0 it will still be scheduled by your operating system and so might not quite get to the speed you want. The burst rate can cause the program to send one than one frame each interval. This is useful as a CAN bus could potentially support 2000 to 8000 frames per second. If you need rapid frame sending your best bet is to set the sending interval to 1-2ms and then adjust the burst
|
||
rate until you get your desired sending rate. Then you can set the number of bytes to send. Ordinarily this would be the full 8 but you can experiment with smaller frames. You can set to send on a specific bus. That’s all the simple settings. It gets a bit more complicated now.</p>
|
||
<p>The “ID Scanning” box has two radio buttons:</p>
|
||
<ol class="arabic simple">
|
||
<li><p>Sequential will go from “Start ID” to “End ID” then reset back to Start over and over.</p></li>
|
||
<li><p>Random will pick IDs at random in the range between Start and End</p></li>
|
||
</ol>
|
||
<p>But, perhaps you don’t want to fuzz IDs like that? The next box is “ID Selection” and the choices are:</p>
|
||
<ol class="arabic simple">
|
||
<li><p>Range of IDs - this uses the aforementioned Start and End IDs</p></li>
|
||
<li><p>Filter list - This causes it to pick frame IDs from the list below either sequentially or randomly according to the radio boxes under “ID Scanning”</p></li>
|
||
</ol>
|
||
<p>The last box is “Bit Scanning”</p>
|
||
<ol class="arabic simple">
|
||
<li><p>Sequential causes it to scan bits in logically sequential order. That is, the first available fuzzing bit is set then the just the second, then the first two, etc. This causes all of the fuzzed bits to sequentially set in order.</p></li>
|
||
<li><p>Sweep causes the system to set the first one, then unset that one and set the second bit, then unset that, etc. Thus the fuzzed bit sweeps and only one fuzzed bit is set at once.</p></li>
|
||
<li><p>Random will randomly pick whether each fuzzed bit is set or not.</p></li>
|
||
</ol>
|
||
<p>In order to fuzz bits you need to set which bits to fuzz and which not to. As listed at the bottom of the window, there is a color code to the 8x8 grid. Clicking cells in the grid will toggle them between their various values. White bits are never set, black bits are always set no matter what, green bits follow the fuzzing pattern you specified in “Bit Scanning” You can also set the bytes directly with the text boxes above the 8x8 grid. Setting a hexadecimal value in these
|
||
boxes will set the relevant bits in the 8x8 grid. You must press the ENTER/RETURN key to set the values. Merely changing the value will not update it (as a safety measure).</p>
|
||
</div>
|
||
<div class="section" id="pulling-the-trigger">
|
||
<h1><span class="section-number">62. </span>Pulling the Trigger<a class="headerlink" href="#pulling-the-trigger" title="Permalink to this headline">¶</a></h1>
|
||
<p>Once you’ve configured everything click “Start Fuzzing” to give it a shot. You will see the number of frames sent so far listed below the button. Approximately four times per second the current value for each byte is copied into the text boxes just above the 8x8 grid. This can be used to see what is going on and to ensure that it is working the way you want it to. You can stop the fuzzing by pushing the start button again.</p>
|
||
</div>
|
||
|
||
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="sphinxsidebar" role="navigation" aria-label="main navigation">
|
||
<div class="sphinxsidebarwrapper">
|
||
<h1 class="logo"><a href="index.html">SavvyCAN</a></h1>
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
<h3>Navigation</h3>
|
||
<ul class="current">
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html">1. Main / Start Up Screen</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#the-main-frame-list">2. The Main Frame List</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#the-bottom-statusbar">3. The Bottom Statusbar</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#the-rest-of-the-main-window">4. The Rest of the Main Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#loading-and-saving-frames">5. Loading And Saving Frames</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#filters">6. Filters</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#what-is-dbc-and-why-would-i-care">7. What is DBC and why would I care?!</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="mainscreen.html#how-dbc-interacts-with-the-main-screen">8. How DBC interacts with the main screen?</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="connectionwindow.html">9. Connection Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="connectionwindow.html#connecting-to-a-dongle">10. Connecting To A Dongle</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="connectionwindow.html#debugging-connection-problems">11. Debugging Connection Problems</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="preferences.html">12. Preference Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="preferences.html#setting-preferences">13. Setting Preferences</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_manager.html">14. DBC File Manager</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_manager.html#working-with-dbc-files">15. Working with DBC Files</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_manager.html#dbc-file-ordering">16. DBC File Ordering</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_editor.html">17. DBC Message Editor</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_editor.html#working-with-nodes">18. Working with Nodes</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dbc_editor.html#working-with-messages">19. Working with Messages</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="signaleditor.html">20. DBC Signal Editor</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="signaleditor.html#defining-and-editing-signals">21. Defining and Editing Signals</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html">22. Graphing Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#creating-a-new-graph">23. Creating a new Graph</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#selecting-a-graph">24. Selecting a Graph</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#editing-a-graph">25. Editing a Graph</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#deleting-graphs">26. Deleting Graphs</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#moving-around">27. Moving Around</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#loading-and-saving-graphs">28. Loading and Saving Graphs</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#real-time-graphing">29. Real Time Graphing</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphwindow.html#hidden-tricks">30. Hidden Tricks</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphsetup.html">31. Graph Setup</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphsetup.html#setting-up-a-graph">32. Setting up a Graph</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphsetup.html#graphing-a-dbc-signal">33. Graphing a DBC Signal</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="graphsetup.html#manual-signal-graphing-or-editing">34. Manual Signal Graphing (Or Editing)</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html">35. Flow View Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#the-purpose-of-flow-view">36. The Purpose of Flow View</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#selecting-an-id-to-flow">37. Selecting an ID to Flow</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#viewing-the-flow">38. Viewing the Flow</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#controlling-the-flow">39. Controlling the Flow</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#additional-control-options">40. Additional control options</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#reference-values">41. Reference Values</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="flowview.html#seeking-to-specific-values">42. Seeking to Specific Values</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="bisector.html">43. Bisector Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="bisector.html#using-the-bisector-window">44. Using the Bisector Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html">45. Sniffer Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#using-the-sniffer-window">46. Using the Sniffer Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#notching-and-unnotching">47. Notching and Unnotching</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#advanced-options">48. Advanced Options</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#never-expire-ids">49. Never Expire IDs</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#mute-notched-bits">50. Mute notched bits</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#fade-inactive-bytes">51. Fade inactive bytes</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="sniffer.html#view-bits">52. View Bits</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="framedetails.html">53. Frame Details Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="framedetails.html#the-purpose-of-frame-details-window">54. The Purpose of Frame Details Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="filecomparison.html">55. File Comparison Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="filecomparison.html#the-purpose-of-the-file-comparator">56. The Purpose of the File Comparator</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="filecomparison.html#the-layout-of-the-differences-list">57. The layout of the differences list</a></li>
|
||
<li class="toctree-l1 current"><a class="current reference internal" href="#">58. Fuzzing Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="#the-purpose-of-fuzzing">59. The Purpose of Fuzzing</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="#fuzzing-is-dangerous">60. Fuzzing is Dangerous</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="#controlling-the-fuzzy-beast">61. Controlling the Fuzzy Beast</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="#pulling-the-trigger">62. Pulling the Trigger</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="isotp_decoder.html">63. ISO-TP Decoder</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="isotp_decoder.html#using-the-iso-tp-decoder">64. Using the ISO-TP Decoder</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="rangestate.html">65. Range State Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="rangestate.html#using-the-range-state-window">66. Using the Range State Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="uds_scanner.html">67. UDS Scan Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="uds_scanner.html#purpose-of-the-uds-scan-window">68. Purpose of the UDS Scan Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="uds_scanner.html#using-the-uds-scan-window">69. Using the UDS Scan Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="playbackwindow.html">70. Playback Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="playbackwindow.html#preparing-frames-for-playback">71. Preparing Frames for Playback</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="playbackwindow.html#playing-back-frames">72. Playing Back Frames</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="playbackwindow.html#playback-status">73. Playback Status</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="customsender.html">74. Custom Sender Window</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="customsender.html#general-overview">75. General Overview</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="customsender.html#layout-of-the-view">76. Layout of the View</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="customsender.html#writing-trigger-rules">77. Writing Trigger Rules</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="customsender.html#writing-modifications">78. Writing Modifications</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html">79. Scripting Interface</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#purpose-of-the-scripting-interface">80. Purpose of the Scripting Interface</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#managing-scripts">81. Managing Scripts</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#getting-script-status">82. Getting Script Status</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#writing-scripts">83. Writing Scripts</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#callback-functions">84. Callback Functions</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#the-host-object">85. The host Object</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#the-can-object">86. The can Object</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#the-isotp-object">87. The isotp Object</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#the-uds-object">88. The uds Object</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="scriptingwindow.html#a-full-example-script">89. A full example script</a></li>
|
||
</ul>
|
||
|
||
<div class="relations">
|
||
<h3>Related Topics</h3>
|
||
<ul>
|
||
<li><a href="index.html">Documentation overview</a><ul>
|
||
<li>Previous: <a href="filecomparison.html" title="previous chapter"><span class="section-number">55. </span>File Comparison Window</a></li>
|
||
<li>Next: <a href="isotp_decoder.html" title="next chapter"><span class="section-number">63. </span>ISO-TP Decoder</a></li>
|
||
</ul></li>
|
||
</ul>
|
||
</div>
|
||
<div id="searchbox" style="display: none" role="search">
|
||
<h3 id="searchlabel">Quick search</h3>
|
||
<div class="searchformwrapper">
|
||
<form class="search" action="search.html" method="get">
|
||
<input type="text" name="q" aria-labelledby="searchlabel" />
|
||
<input type="submit" value="Go" />
|
||
</form>
|
||
</div>
|
||
</div>
|
||
<script>$('#searchbox').show(0);</script>
|
||
</div>
|
||
</div>
|
||
<div class="clearer"></div>
|
||
</div>
|
||
<div class="footer">
|
||
©2018, EVTV.
|
||
|
||
|
|
||
Powered by <a href="http://sphinx-doc.org/">Sphinx 3.5.4</a>
|
||
& <a href="https://github.com/bitprophet/alabaster">Alabaster 0.7.8</a>
|
||
|
||
|
|
||
<a href="_sources/fuzzingwindow.rst.txt"
|
||
rel="nofollow">Page source</a>
|
||
</div>
|
||
|
||
|
||
|
||
|
||
</body>
|
||
</html> |