drrun on Microsoft Word

32 views
Skip to first unread message

Ghost is Vulnerable

unread,
Jan 18, 2022, 6:22:31 AM1/18/22
to DynamoRIO Users
I am analyzing attack surface for winword from latest office365 where looking for interesting functions to fuzz. i am  generating code coverage for a test file .docx with Drrun.exe like below image
149909763-a0d5edac-9925-4b38-9a91-3eb0aad57166.png


while running drrun, the target application(microsoft word) is not closing by default, hence not able to generating code coverage log file. however this works on other application like Adobe or Foxit. but not in the case of winword.exe


if i forcefully close the application by ctrl+c  or terminate the application by default, it generates the code coverage but it is not in the proper format. and if i open this coverage file using ida light house plugin, it says unable to parse the file

Capture.PNG

sharma...@google.com

unread,
Jan 18, 2022, 1:29:18 PM1/18/22
to DynamoRIO Users
Hi,
Did you see any logs or assert failures that might help us figure out the problem? Try using the debug build ("Debug build" section on https://dynamorio.org/page_building.html) and log files (https://dynamorio.org/page_logging.html).

Abhinav

sharma...@google.com

unread,
Jan 21, 2022, 11:05:04 AM1/21/22
to DynamoRIO Users
Reply all
Reply to author
Forward
0 new messages