Skip to content
  • Categories
  • KForum
  • KClub
  • KClub Discord
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Kaspersky Beta

  1. Home
  2. ENGLISH USER FORUM
  3. Home
  4. Kaspersky
  5. Archive
  6. 2020
  7. [2020] GUI/Help
  8. Peach fuzzing with avpui.exe

Peach fuzzing with avpui.exe

Scheduled Pinned Locked Moved [2020] GUI/Help
4 Posts 2 Posters 4.5k Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H Offline
    H Offline
    Helios_07
    wrote on last edited by Jarvis
    #1

    <p><strong>Real system:</strong></p>
    <p><strong>Windows 10 64-bit, Version 1803</strong></p>
    <p><strong>KIS 20.0.0.454 de app + drv verifier enabled</strong></p>
    <p><strong>Reproduction steps:</strong></p>
    <p><span>Important is that Traces are enabled or it wont work!</span></p>
    <p><span>When i hand a fuzzed dll file to avpui.exe with Peach Fuzzer ,with the start a process option, Peach logs an Illegal Instruction Violation starting at avpuimain!SoundPlayW+0x00000000000a013b.</span></p>
    <p><span>KIS isnt effected because an extra process is started.</span></p>
    <p><span>It works with any fuzzed dll and some other filetypes.</span></p>
    <p><span>I attached the peach logs.</span></p>
    <p><strong></strong></p>
    <p><span></span></p>

    PC:
    Windows 10 64-bit Version 20H2
    Build 19042.985
    Intel Core i10-10900K @ 3,7GHZ
    32,0 GB-RAM
    NVIDIA Geforce RTX 2080 TI 11GB
    KIS 21.4.8.292
    KPM 9.0.2.15298(o)
    Forum Signature from 25.May.2021

    1 Reply Last reply
    0
    • D Offline
      D Offline
      Dmitriy.Pisarets
      Kaspersky Lab
      wrote on last edited by
      #2

      <p>@helios_07 hello! Can you  create application dump and OS dump also? </p>

      H 1 Reply Last reply
      0
      • D Dmitriy.Pisarets

        <p>@helios_07 hello! Can you  create application dump and OS dump also? </p>

        H Offline
        H Offline
        Helios_07
        wrote on last edited by
        #3

        <p>@dmitriy-pisarets</p>
        <p>Hi dmitriy,</p>
        <p>I dont think i cant create a dump, i just use the graphical interface of peach to do that and the avpui process runs for about 2 sec only.</p>
        <p>Thats the Peach Version i use :<a href="https://cloud.qainfo.ru/s/8mnuwKBQxiv4J8p" target="_blank" rel="noopener">https://cloud.qainfo.ru/s/8mnuwKBQxiv4J8p</a></p>
        <p>The gui PeachFuzzBang.exe</p>
        <p>Under general, template file any dll, fuzzed file name fuzzed.dll, under debugger start a proces command line the path to avpui.exe fuzzed.dll.</p>
        <p>Then start fuzzing, if everything works peach logs the violation as described aboth.</p>
        <p>I hope those steps help to reproduce it at your end.</p>

        PC:
        Windows 10 64-bit Version 20H2
        Build 19042.985
        Intel Core i10-10900K @ 3,7GHZ
        32,0 GB-RAM
        NVIDIA Geforce RTX 2080 TI 11GB
        KIS 21.4.8.292
        KPM 9.0.2.15298(o)
        Forum Signature from 25.May.2021

        1 Reply Last reply
        0
        • H Offline
          H Offline
          Helios_07
          wrote on last edited by Helios_07
          #4

          <p>KIS dump as requested: <a href="https://cloud.qainfo.ru/s/2eGOkCyCrlbJe6D" target="_blank" rel="noopener">https://cloud.qainfo.ru/s/2eGOkCyCrlbJe6D</a></p>
          <p>OS dump: <a href="https://cloud.qainfo.ru/s/5WvyeVjRYsqs4OQ" target="_blank" rel="noopener">https://cloud.qainfo.ru/s/5WvyeVjRYsqs4OQ</a></p>

          PC:
          Windows 10 64-bit Version 20H2
          Build 19042.985
          Intel Core i10-10900K @ 3,7GHZ
          32,0 GB-RAM
          NVIDIA Geforce RTX 2080 TI 11GB
          KIS 21.4.8.292
          KPM 9.0.2.15298(o)
          Forum Signature from 25.May.2021

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • KForum
          • KClub
          • KClub Discord