1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
|
/*
* (C) 2015,2016 Jack Lloyd
*
* Botan is released under the Simplified BSD License (see license.txt)
*/
#include "driver.h"
#include <botan/tls_client.h>
class Fuzzer_TLS_Client_Creds : public Credentials_Manager
{
public:
std::string psk_identity_hint(const std::string&, const std::string&) override { return "psk_hint"; }
std::string psk_identity(const std::string&, const std::string&, const std::string&) override { return "psk_id"; }
SymmetricKey psk(const std::string&, const std::string&, const std::string&) override
{
return SymmetricKey("AABBCCDDEEFF00112233445566778899");
}
};
void fuzz(const uint8_t in[], size_t len)
{
if(len == 0)
return;
auto dev_null = [](const byte[], size_t) {};
auto ignore_alerts = [](TLS::Alert, const byte[], size_t) {};
auto ignore_hs = [](const TLS::Session&) { abort(); return true; };
TLS::Session_Manager_Noop session_manager;
TLS::Policy policy;
TLS::Protocol_Version client_offer = TLS::Protocol_Version::TLS_V12;
TLS::Server_Information info("server.name", 443);
const std::vector<std::string> protocols_to_offer = { "fuzz/1.0", "http/1.1", "bunny/1.21.3" };
Fuzzer_TLS_Client_Creds creds;
TLS::Client client(dev_null,
dev_null,
ignore_alerts,
ignore_hs,
session_manager,
creds,
policy,
fuzzer_rng(),
info,
client_offer,
protocols_to_offer);
try
{
while(len > 0)
{
const size_t write_len = in[0];
const size_t left = len - 1;
const size_t consumed = std::min(left, write_len);
client.received_data(in + 1, consumed);
in += consumed + 1;
len -= consumed + 1;
}
}
catch(std::exception& e)
{
}
}
|