Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
أدوات/GitHubGitHub/qualcomm/afltriage
تحليل الثغرات الأمنيةمصممي الأخطاءالاختبار العشوائي
GitHubqualcomm/afltriage

AFLTriage

أداة تصنيف الأعطال المحمولة المستندة إلى مصحح الأخطاء لمخرجات الاختبار العشوائي. تدعم التصنيف المتوازي، وإزالة الأعطال المكررة، وتحليل تقارير العازل، وتنسيقات تقارير متعددة (نص، JSON).

عرض المستودع
145161منذ 4 أشهرتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

AFLTriage

AFLTriage هي أداة لتصنيف ملفات الإدخال المتسببة في تعطل البرنامج باستخدام مصحح أخطاء. صُممت لتكون محمولة ولا تتطلب أي تبعيات وقت تشغيل، باستثناء libc ومصحح أخطاء خارجي. تدعم تصنيف الأعطال الناتجة عن أي برنامج، وليس فقط AFL، لكنها تتعرف على أدلة AFL بشكل خاص، ومن هنا جاء الاسم.

تشمل بعض الميزات البارزة:

  • تنسيقات تقارير متعددة: نصي، JSON، و JSON مصحح أخطاء خام
  • تصنيف الأعطال بالتوازي
  • إزالة التكرار في الأعطال
  • تحليل تقارير المُعقّم (Sanitizer)
  • دعم الأهداف الثنائية مع أو بدون رموز/معلومات تصحيح
  • سيتم شرح الكود المصدري والمتغيرات في التقارير للسياق

حاليًا، يدعم AFLTriage GDB فقط وقد تم اختباره فقط على أهداف Linux C/C++. لاحظ أن AFLTriage لا يصنف الأعطال حسب احتمالية الاستغلال. تصنيف قابلية الاستغلال بدقة يعتمد بشكل كبير على الهدف والسيناريو، ومن الأفضل تركه للأدوات المتخصصة والمحللين الخبراء.

الاستخدام

استخدام AFLTriage بسيط جدًا. تحتاج إلى ملفات الإدخال لتصنيفها، ودليل إخراج للتقارير، والملف الثنائي ووسائطه لتصنيفها.

مثال:

root@kitploit:~
$ afltriage -i fuzzing_directory -o reports ./target_binary --option-one @@
AFLTriage v1.0.0

[+] GDB is working (GNU gdb (Ubuntu 8.1.1-0ubuntu1) 8.1.1 - Python 3.6.9 (default, Jan 26 2021, 15:33:00))
[+] Image triage cmdline: "./target_binary --option-one @@"
[+] Reports will be output to directory "reports"
[+] Triaging AFL directory fuzzing_directory/ (41 files)
[+] Triaging 41 testcases
[+] Using 24 threads to triage
[+] Triaging   [41/41 00:00:02] [####################] CRASH: ASAN detected heap-buffer-overflow in buggy_function after a READ leading to SIGABRT (si_signo=6) / SI_TKILL (si_code=-6)
[+] Triage stats [Crashes: 25 (unique 12), No crash: 16, Errored: 0]

كما في AFL، يتم استبدال @@ بمسار الملف المراد تصنيفه. سيتولى AFLTriage الباقي.

البناء والتشغيل

ستحتاج إلى بيئة بناء Rust عاملة. بمجرد تثبيت cargo و Rust، يصبح البناء والتشغيل بسيطًا:

root@kitploit:~
cd afltriage-rs/
cargo run --help

<compilation>

    Finished dev [unoptimized + debuginfo] target(s) in 0.33s
     Running `target/debug/afltriage --help`

<AFLTriage usage>
...

الاستخدام الموسع

root@kitploit:~
afltriage 1.0.0
Quickly triage and summarize crashing testcases

USAGE:
    afltriage -i <input>... -o <output> <command>...

OPTIONS:
    -i <input>...
            A list of paths to a testcase, directory of testcases, AFL directory, and/or directory of AFL directories to
            be triaged. Note that this arg takes multiple inputs in a row (e.g. -i input1 input2...) so it cannot be the
            last argument passed to AFLTriage -- this is reserved for the command.
    -o <output>
            The output directory for triage report files. Use '-' to print entire reports to console.

    -t, --timeout <timeout>
            The timeout in milliseconds for each testcase to triage. [default: 60000]

    -j, --jobs <jobs>                                
            How many threads to use during triage.

        --report-formats <report_formats>...
            The triage report output formats. Multiple values allowed: e.g. text,json. [default: text]  [possible
            values: text, json, rawjson]
        --bucket-strategy <bucket_strategy>
            The crash deduplication strategy to use. [default: afltriage]  [possible values: none, afltriage,
            first_frame, first_frame_raw, first_5_frames, function_names, first_function_name]
        --child-output                               
            Include child output in triage reports.

        --child-output-lines <child_output_lines>
            How many lines of program output from the target to include in reports. Use 0 to mean unlimited lines (not
            recommended). [default: 25]
        --stdin                                      
            Provide testcase input to the target via stdin instead of a file.

        --profile-only
            Perform environment checks, describe the inputs to be triaged, and profile the target binary.

        --skip-profile                               
            Skip target profiling before input processing.

        --debug                                      
            Enable low-level debugging output of triage operations.

    -h, --help                                       
            Prints help information

    -V, --version                                    
            Prints version information


ARGS:
    <command>...    
            The binary executable and args to execute. Use '@@' as a placeholder for the path to the input file or
            --stdin. Optionally use -- to delimit the start of the command.

المشاريع ذات الصلة

  • GDB Exploitable - مصدر إلهام كبير لـ AFLTriage
  • Crashwalk
  • afl-collect من afl-utils

الترخيص

AFLTriage مرخصة بموجب ترخيص BSD 3-clause "New" أو "Revised". راجع LICENSE لمزيد من التفاصيل.

تنزيل الأداة