<div dir="ltr"><div><div><div><div>further, it stopped in case maddr:<br><img alt="内嵌图片 1" src="cid:ii_14cc715f2f4f4b90" height="93" width="381"> <br></div>just this "shad->ram->label(a-><a href="http://val.ma">val.ma</a>+a->off, ls)" sentence.<br></div>because it is not x86_64,so the ram is SdDir32 *ram<br><br></div> <img alt="内嵌图片 2" src="cid:ii_14cc718760e8811c" height="325" width="226"><br></div><br>but there is no "label" in SdDir32:<br><br><img alt="内嵌图片 4" src="cid:ii_14cc719342ea6b16" height="248" width="381"><br><div><div><div><div> so there is segfault,right?<br><br></div><div>Please correct me!<br></div><div>Thanks a lot!<br></div></div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-17 4:21 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">i try to locate the function where it stopped:<br><div><div><img src="cid:ii_i8lbmpuy0_14cc6727ece159af" height="122" width="397"><br></div><div>and it stopped in this switch-case :<br></div><div><img src="cid:ii_i8lbmpvh1_14cc6727ece159af" height="246" width="397"><br></div><div> <br></div><div>i do not know why?<br><br></div><div>Thanks a lot!<br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-17 2:31 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<div><div class="h5"><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div>the question is this:<br><img src="cid:ii_i8l7btv40_14cc6043ace43d1f" height="168" width="397"><br></div>it will call this method:<br><img alt="内嵌图片 1" src="cid:ii_14cc610fa93f1acf" height="101" width="397"><br></div><div><br>the segfault occurs when it labels the phys addr in memory?<br></div><div>does it have no access to operate that mem?<br><br></div><div>Thanks a lot?<br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-16 21:04 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div><div><div><div><div>i do not know which step is wrong:<br></div>i use the avd to create the img:<img src="cid:ii_i8kw2o0r0_14cc4e3c93ee5f43" height="106" width="401"><br></div>and the use pandaConvert.py to convert them to qcow2;<br></div>then i use runpandroid.py(-m 512) to record and -m 512 to replay.<br></div>the size of my host system is :<img src="cid:ii_i8kw67qb1_14cc4e64fee7cf22" height="11" width="401"><br><br></div>why segfault while applying taint labels?it shouldn't.<br></div><div><div><div><div><div><br></div></div></div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-16 20:12 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>thanks first.<br></div>the segfault again...<br></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-16 17:10 GMT-04:00 Brendan Dolan-Gavitt <span dir="ltr"><<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">The message about Hugetlb can be ignored -- it is just an optimization if HugeTLB is available on your system [1].<div><br></div><div><div>In general, the taint system uses 16 times as much RAM as the guest system has, because it is trying to store two 64-bit pointers per byte of guest memory in order to keep track of the labels that a byte of memory has. This tends to make the taint system a lot faster, since many taint operations simply become copies from one place to another.</div><div><br></div><div>Is the taint analysis working now?</div><div><br></div><div>-Brendan</div><div><br></div><div>[1] <a href="http://linuxgazette.net/155/krishnakumar.html" target="_blank">http://linuxgazette.net/155/krishnakumar.html</a></div></div></div><div><div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Apr 16, 2015 at 5:19 AM, xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div>sorry about the repeat question of "record -m 512"..i am just in a short circuit...<br></div>now the thing is:<br></div>the guest mem size is 512 when i record,mu host mem is large enough.<br><div><div><img src="cid:ii_i8jya3u90_14cc181b7bdb0d8f" height="94" width="381"><br><br></div><div>when replay,it just try to allocate so large size,but why?<br></div><div><img src="cid:ii_i8jya3ut1_14cc181b7bdb0d8f" height="35" width="381"><br><br></div><div>thanks a lot!<br></div><div><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-15 23:25 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div>Hi,Brendan,<br></div>i have tried it and segfault again.<br></div><div>my host is 16G which is large enough.<br></div><div>I think maybe this is not caused by size of mem.<br></div><div>Please correct me!<br></div><div>Thanks a lot!<br></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-15 22:54 GMT-04:00 xiaojuan Li <span dir="ltr"><<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>i see. i am going to try.<br></div>Thanks very much for your great patience! <br></div><div class="gmail_extra"><br><div class="gmail_quote">2015-04-15 22:49 GMT-04:00 Brendan Dolan-Gavitt <span dir="ltr"><<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>></span>:<div><div><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Find the place in runandroid.py where it sets the amount of RAM. The<br>
line looks like:<br>
<br>
panda_cli.extend(["-kernel", kernel, "-initrd", initrd,<br>
'-global', 'goldfish_nand.system_path={0}'.format(system),<br>
'-global', 'goldfish_nand.user_data_path={0}'.format(data),<br>
'-global', 'goldfish_nand.cache_path={0}'.format(cache),<br>
'-append', KERNEL_CL,<br>
'-m', '2G', '-no-reboot', '-monitor', 'telnet:localhost:4321,server,nowait',<br>
'-show-cursor', '-serial', 'stdio', '-serial',<br>
'telnet:localhost:4421,server,nowait',<br>
'-display', 'sdl', '-global',<br>
'goldfish_mmc.sd_path={0}'.format(sdcard), '-android', '-S'])<br>
<br>
And change the 2G to 512. Then recreate the recording using<br>
"begin_record recordingname", and run the replay with -m 512 on the<br>
command line.<br>
<br>
For a recording where the guest OS uses 512M RAM, you will need 8GB on<br>
the host to replay with taint. If that is too much, you can try<br>
changing from 512 to 256 or lower, but you may run into trouble<br>
getting Android apps to run correctly.<br>
<br>
Hope this helps,<br>
Brendan<br>
<div><div><br>
On Wed, Apr 15, 2015 at 10:45 PM, xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
> i have a question that:i set the mem of img created by avd is 8G?and then<br>
> when i boot the emulator i modify the runpandroid.py with -m 512 to<br>
> begin_record?<br>
> (i tried to use "begin_record name -m 512", it seems not right.)<br>
> i do not clear enough that "record with -m 512"<br>
> Thanks a lot<br>
><br>
> 2015-04-15 22:39 GMT-04:00 xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
><br>
>> i use the runpandroid.py to create, and the mem is 2G.<br>
>> I am going to set the required mem to do and thanks a lot.<br>
>><br>
>> 2015-04-15 22:28 GMT-04:00 Brendan Dolan-Gavitt <<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>>:<br>
>><br>
>>> How much RAM is installed on the system you're trying to use to replay? A<br>
>>> recording with 512M will need at least 8GB of RAM to replay with taint.<br>
>>><br>
>>> -Brendan<br>
>>><br>
>>> On Wed, Apr 15, 2015 at 10:27 PM, xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>> wrote:<br>
>>>><br>
>>>> it seems does not work.<br>
>>>> i set the -m 512 before record,when replay it still shows segmentation<br>
>>>> fault.<br>
>>>><br>
>>>> 2015-04-15 22:09 GMT-04:00 Brendan Dolan-Gavitt <<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>>:<br>
>>>><br>
>>>>> Yes, you need to record with -m 512. Just trying to replay the existing<br>
>>>>> recording with -m 512 will not work.<br>
>>>>><br>
>>>>> -Brendan<br>
>>>>><br>
>>>>> On Wed, Apr 15, 2015 at 10:08 PM, xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>> wrote:<br>
>>>>>><br>
>>>>>> the question is can begin_record with "-m 512" args?<br>
>>>>>> I just set the img's ram size is 512.and if i replay it with "-m<br>
>>>>>> 512",it just be aborted<br>
>>>>>><br>
>>>>>> Thanks<br>
>>>>>><br>
>>>>>> 2015-04-15 22:01 GMT-04:00 Brendan Dolan-Gavitt <<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>>:<br>
>>>>>><br>
>>>>>>> The problem is that you are giving the system too much RAM – you need<br>
>>>>>>> to remake the recording with -m 512. Currently the taint system tries to<br>
>>>>>>> reserve 16x as much RAM as the guest system for taint, so for 2GB of guest<br>
>>>>>>> RAM it's trying to reserve 32GB.<br>
>>>>>>><br>
>>>>>>> -Brendan<br>
>>>>>>><br>
>>>>>>> On Wed, Apr 15, 2015 at 9:08 PM, xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>> wrote:<br>
>>>>>>>><br>
>>>>>>>> Hi,Brendan,<br>
>>>>>>>> I have done it from the begin(convert img to qcow2),then i replay it<br>
>>>>>>>> with taint2 plugin,<br>
>>>>>>>> when it tstringsearch the maching, it just shows "segmentation<br>
>>>>>>>> fault",but i notice that it also tstringsearch the unmatching and there is<br>
>>>>>>>> no segfault.<br>
>>>>>>>> here is, my test string is "passwordisqemua":<br>
>>>>>>>><br>
>>>>>>>><br>
>>>>>>>><br>
</div></div><div><div>>>>>>>>> Thanks!<br>
>>>>>>>><br>
>>>>>>>> 2015-04-15 13:05 GMT-04:00 Brendan Dolan-Gavitt <<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>>:<br>
>>>>>>>><br>
>>>>>>>>> Hi,<br>
>>>>>>>>><br>
>>>>>>>>> It looks like the problem is that it's trying to allocate much more<br>
>>>>>>>>> RAM than you are likely to have available: 34359738368 bytes, or 32 GiB.<br>
>>>>>>>>> This may be because you are using a fairly large amount of RAM for the<br>
>>>>>>>>> Android system; could you try reducing that to 512M and seeing if that fixes<br>
>>>>>>>>> the problem?<br>
>>>>>>>>><br>
>>>>>>>>> -Brendan<br>
>>>>>>>>><br>
>>>>>>>>> On Wed, Apr 15, 2015 at 4:26 AM, xiaojuan Li<br>
>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
>>>>>>>>>><br>
>>>>>>>>>> could you share any ways how do you do with it?even though now<br>
>>>>>>>>>> the bug is not fixed?<br>
>>>>>>>>>> Thanks a lot!<br>
>>>>>>>>>><br>
>>>>>>>>>> 2015-04-13 22:05 GMT-04:00 Brendan Dolan-Gavitt<br>
>>>>>>>>>> <<a href="mailto:mooyix@gmail.com" target="_blank">mooyix@gmail.com</a>>:<br>
>>>>>>>>>><br>
>>>>>>>>>>> Yes, I downloaded the .rr and have reproduced your issue. I will<br>
>>>>>>>>>>> look into it and see if I can get the bug fixed!<br>
>>>>>>>>>>><br>
>>>>>>>>>>> -Brendan<br>
>>>>>>>>>>><br>
>>>>>>>>>>> On Mon, Apr 13, 2015 at 10:04 PM, xiaojuan Li<br>
>>>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
>>>>>>>>>>>><br>
>>>>>>>>>>>> could you download that .rr correctly?<br>
>>>>>>>>>>>><br>
>>>>>>>>>>>> 2015-04-13 10:05 GMT-04:00 xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>><br>
>>>>>>>>>>>>> yeah,i did not get seg fault when i reproduce the tainted<br>
>>>>>>>>>>>>> instructions tutorial.<br>
>>>>>>>>>>>>> Thanks for your patience very much!<br>
>>>>>>>>>>>>> your guys' work is great! do not say sorry.<br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>> my command line is:(in /qemu/arm-softmmu<br>
>>>>>>>>>>>>> directory)./qemu-system-arm -m 2G -replay ime4-13 -M android_arm -kernel<br>
>>>>>>>>>>>>> /dev/null -android -panda "stringsearch:name=1;tstringsearch;tainted_instr";<br>
>>>>>>>>>>>>> the content of 1_search_strings.txt is: "cipher";<br>
>>>>>>>>>>>>> here is my .rr file:<br>
>>>>>>>>>>>>> <a href="http://pan.baidu.com/s/1gdCfTSn" target="_blank">http://pan.baidu.com/s/1gdCfTSn</a><br>
>>>>>>>>>>>>> (sorry for taking so long time to upload .rr)<br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>> Thanks again!<br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>> 2015-04-13 8:58 GMT-04:00 Leek, Timothy - 0559 - MITLL<br>
>>>>>>>>>>>>> <<a href="mailto:tleek@ll.mit.edu" target="_blank">tleek@ll.mit.edu</a>>:<br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> Uninit taint plugin *should* display at the end of the run.<br>
>>>>>>>>>>>>>> That is not an error. It is just a message. You aren't getting a seg fault<br>
>>>>>>>>>>>>>> when you reproduce the tainted instructions tutorial, though. Right?<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> I don't know what's wrong with your android run. We could try<br>
>>>>>>>>>>>>>> to reproduce and debug. Can you give us your replay? Package it up with<br>
>>>>>>>>>>>>>> scripts/rrpack.py. Stick the .rr file somewhere we can get it. And give us<br>
>>>>>>>>>>>>>> your complete command line. And the string search file.<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> That said -- we are fairly swamped right now. So might take a<br>
>>>>>>>>>>>>>> bit. Sorry!<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> Cheers.<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> Tim<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> ________________________________<br>
>>>>>>>>>>>>>> From: xiaojuan Li [<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>]<br>
>>>>>>>>>>>>>> Sent: Monday, April 13, 2015 8:27 AM<br>
>>>>>>>>>>>>>> To: Leek, Timothy - 0559 - MITLL; <a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>; Brendan<br>
>>>>>>>>>>>>>> Dolan-Gavitt<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> Subject: Re: [panda-users] taint segmentation fault<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> let me describe how can i get my test snp:<br>
>>>>>>>>>>>>>> first i boot android emulator,begin_record, do some operations<br>
>>>>>>>>>>>>>> in emulator,end_record. then i use it to replay to taint the data i input<br>
>>>>>>>>>>>>>> before.<br>
>>>>>>>>>>>>>> (by the way, though i can get the result of the tutorial,it<br>
>>>>>>>>>>>>>> shows "uninit taint plugin" end of the result).<br>
>>>>>>>>>>>>>> Thanks!<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> 2015-04-13 8:14 GMT-04:00 xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>> Thanks first.<br>
>>>>>>>>>>>>>>> I tried it before and can get the result described in the<br>
>>>>>>>>>>>>>>> tutorial,but when turn to my snp, it still shows "segfault".<br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>> 2015-04-13 7:26 GMT-04:00 Leek, Timothy - 0559 - MITLL<br>
>>>>>>>>>>>>>>> <<a href="mailto:tleek@ll.mit.edu" target="_blank">tleek@ll.mit.edu</a>>:<br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> Maybe try git pull. Then make distclean in qemu dir. Then<br>
>>>>>>>>>>>>>>>> make. Then try the tutorial. Should work.<br>
>>>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>> Tim Leek<br>
>>>>>>>>>>>>>>>> Technical Staff<br>
>>>>>>>>>>>>>>>> Cyber System Assessments<br>
>>>>>>>>>>>>>>>> MIT Lincoln Laboratory<br>
>>>>>>>>>>>>>>>> <a href="tel:781-981-2975" value="+17819812975" target="_blank">781-981-2975</a><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> From: xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>> Date: Sunday, April 12, 2015 at 11:41 PM<br>
>>>>>>>>>>>>>>>> To: Brendan Dolan-Gavitt <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>>,<br>
>>>>>>>>>>>>>>>> "<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>" <<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> Subject: Re: [panda-users] taint segmentation fault<br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> yeah.i fail to taint both in using sshkeygen and my test<br>
>>>>>>>>>>>>>>>> snp.<br>
>>>>>>>>>>>>>>>> here is the result of following the steps in the tutorial:<br>
</div></div><div><div>>>>>>>>>>>>>>>>> Thanks!<br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> 2015-04-13 11:34 GMT+08:00 Brendan Dolan-Gavitt<br>
>>>>>>>>>>>>>>>> <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>>:<br>
>>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> Are you able to follow the steps in the tutorial (using the<br>
>>>>>>>>>>>>>>>>> sshkeygen<br>
>>>>>>>>>>>>>>>>> replay)? Or does that fail as well?<br>
>>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> -Brendan<br>
>>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> On Sun, Apr 12, 2015 at 11:27 PM, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
>>>>>>>>>>>>>>>>> > thanks first. i cannot either.<br>
>>>>>>>>>>>>>>>>> > just segfault while tainting.<br>
>>>>>>>>>>>>>>>>> ><br>
>>>>>>>>>>>>>>>>> ><br>
>>>>>>>>>>>>>>>>> > 2015-04-13 4:52 GMT+08:00 Leek, Timothy - 0559 - MITLL<br>
>>>>>>>>>>>>>>>>> > <<a href="mailto:tleek@ll.mit.edu" target="_blank">tleek@ll.mit.edu</a>>:<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> Also, just a check. Are you able to reproduce the<br>
>>>>>>>>>>>>>>>>> >> results here?<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> <a href="https://github.com/moyix/panda/blob/master/docs/tainted_instructions.md" target="_blank">https://github.com/moyix/panda/blob/master/docs/tainted_instructions.md</a><br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> --<br>
>>>>>>>>>>>>>>>>> >> Tim Leek<br>
>>>>>>>>>>>>>>>>> >> Technical Staff<br>
>>>>>>>>>>>>>>>>> >> Cyber System Assessments<br>
>>>>>>>>>>>>>>>>> >> MIT Lincoln Laboratory<br>
>>>>>>>>>>>>>>>>> >> <a href="tel:781-981-2975" value="+17819812975" target="_blank">781-981-2975</a><br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> From: Brendan Dolan-Gavitt <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>><br>
>>>>>>>>>>>>>>>>> >> Date: Sunday, April 12, 2015 at 4:04 PM<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> To: xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>>> >> Cc: "<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>" <<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>><br>
>>>>>>>>>>>>>>>>> >> Subject: Re: [panda-users] taint segmentation fault<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> A few things:<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> 1. Did you make sure to do a make clean and then re-run<br>
>>>>>>>>>>>>>>>>> >> build.sh after<br>
>>>>>>>>>>>>>>>>> >> updating? I got a segfault just after taint was turned<br>
>>>>>>>>>>>>>>>>> >> on as well until I<br>
>>>>>>>>>>>>>>>>> >> did a make clean and re-ran build.sh.<br>
>>>>>>>>>>>>>>>>> >> 2. Are you running this on a 64-bit system? What kernel<br>
>>>>>>>>>>>>>>>>> >> version?<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> -Brendan<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >> On Sun, Apr 12, 2015 at 9:16 AM, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>>> >> wrote:<br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>> any suggestions? about segmentation fault?<br>
>>>>>>>>>>>>>>>>> >>> and after my test,I make sure it is not caused by<br>
>>>>>>>>>>>>>>>>> >>> insufficient memory.<br>
>>>>>>>>>>>>>>>>> >>> Thanks a lot!<br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>> 2015-04-11 11:59 GMT+08:00 xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>> excuse me:<br>
>>>>>>>>>>>>>>>>> >>>> I try to fix the segmentation error:<br>
>>>>>>>>>>>>>>>>> >>>> and find this piece of code:<br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>> do you mean that it doesn't support so large byte?or<br>
>>>>>>>>>>>>>>>>> >>>> it doesn't support<br>
>>>>>>>>>>>>>>>>> >>>> for android arm?<br>
>>>>>>>>>>>>>>>>> >>>> in the doc I noticed that network tainting is not<br>
>>>>>>>>>>>>>>>>> >>>> supported for arm<br>
>>>>>>>>>>>>>>>>> >>>> architecture,and the string I tainted was something<br>
>>>>>>>>>>>>>>>>> >>>> may go through the<br>
>>>>>>>>>>>>>>>>> >>>> network.<br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>> Thanks!<br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>> 2015-04-09 21:30 GMT+08:00 xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>> Now that the panda <a href="http://taint.md" target="_blank">taint.md</a> is not fresh,can you guys<br>
>>>>>>>>>>>>>>>>> >>>>> give me some<br>
>>>>>>>>>>>>>>>>> >>>>> help?<br>
>>>>>>>>>>>>>>>>> >>>>> I use the replay plugin,here is my command and the<br>
>>>>>>>>>>>>>>>>> >>>>> result.<br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>> the content of pk_search_strings.txt is :"sdt"<br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>> I am confused here:in the paper— Repeatable reverse<br>
>>>>>>>>>>>>>>>>> >>>>> with panda:<br>
>>>>>>>>>>>>>>>>> >>>>> :<br>
>>>>>>>>>>>>>>>>> >>>>> it is clear that:if I use the stringsearch and taint<br>
>>>>>>>>>>>>>>>>> >>>>> plugin,when it<br>
>>>>>>>>>>>>>>>>> >>>>> matches, the taint label will be put and then taint<br>
>>>>>>>>>>>>>>>>> >>>>> action will start.but<br>
>>>>>>>>>>>>>>>>> >>>>> when I use it, it seems wrong(the picture showed<br>
>>>>>>>>>>>>>>>>> >>>>> before):no taint action<br>
>>>>>>>>>>>>>>>>> >>>>> execute,and i am confused about the tstringsearch's<br>
>>>>>>>>>>>>>>>>> >>>>> result.<br>
>>>>>>>>>>>>>>>>> >>>>> how can i use it to analysis?<br>
>>>>>>>>>>>>>>>>> >>>>> Thanks a lot!<br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>> 2015-04-08 10:14 GMT+08:00 xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>> I get the replay file by running runandroid script.<br>
>>>>>>>>>>>>>>>>> >>>>>> and i use<br>
>>>>>>>>>>>>>>>>> >>>>>> qemu-system-arm command just to do some replay work.<br>
>>>>>>>>>>>>>>>>> >>>>>> I may not understand you at all in this emal.do you<br>
>>>>>>>>>>>>>>>>> >>>>>> mean that i should<br>
>>>>>>>>>>>>>>>>> >>>>>> gdb the original program rather than the record<br>
>>>>>>>>>>>>>>>>> >>>>>> file?<br>
>>>>>>>>>>>>>>>>> >>>>>> Thansk<br>
>>>>>>>>>>>>>>>>> >>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>> 2015-04-08 9:52 GMT+08:00 Brendan Dolan-Gavitt<br>
>>>>>>>>>>>>>>>>> >>>>>> <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> Hmm. gdb should normally stop when you get a<br>
>>>>>>>>>>>>>>>>> >>>>>>> segfault.<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> Are you by any chance running PANDA using the<br>
>>>>>>>>>>>>>>>>> >>>>>>> runandroid script? If<br>
>>>>>>>>>>>>>>>>> >>>>>>> so, you will need to instead invoke PANDA manually,<br>
>>>>>>>>>>>>>>>>> >>>>>>> i.e.:<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> gdb --args arm-softmmu/qemu-system-arm [...]<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> And then once it crashes, type "bt" at the gdb<br>
>>>>>>>>>>>>>>>>> >>>>>>> prompt to get a<br>
>>>>>>>>>>>>>>>>> >>>>>>> backtrace.<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> -Brendan<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>> On Tue, Apr 7, 2015 at 9:47 PM, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>>> >>>>>>> wrote:<br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>> when gdb,it shows:<br>
>>>>>>>>>>>>>>>>> >>>>>>>> and then i see the log:it shows segfault:<br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>> 2015-04-08 9:03 GMT+08:00 xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>> maybe i am wrong.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> i use the command<br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>> line:"taint2:label_mode=binary,query_outgoing_network=1"and I found that<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> when i use taint2, after it loads<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> panda_taint2.so,it<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> shows:"taint2:instructed not to inline taint ops<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> .success".<br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>> 2015-04-08 8:54 GMT+08:00 xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> ok.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> 1.I want to use taint plugin to get information<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> about some<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> functions(of course, it is closed-source),so I<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> think I can stringsearch<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> potential data and then taint them and next I<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> can locate the functions which<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> solves these data.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> 2.the command line I used is :<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> stringsearch:name=***;taint2:tainted_instructions=1.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> thanks<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> 2015-04-08 8:40 GMT+08:00 Brendan Dolan-Gavitt<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> Could you provide:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> 1. What information you're trying to get<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> 2. The command line you're using to run PANDA<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> with the taint2<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> plugin<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> ?<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> Right now I believe taint2 does not produce<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> very much output by<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> default. Instead you use the -pandalog<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> <filename> command line option, and<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> taint2 will write its results there in pandalog<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> format; you can then read<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> them using pandalog_reader (see<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> panda/pandalog_reader.c for details on that<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> tool).<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> -Brendan<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> On Tue, Apr 7, 2015 at 8:32 PM, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> when I tried taint2,it showed the same error<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> with taint1, the<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> olny difference is that taint2 has no segfault<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> error,just uninit taint<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> plugin.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> 2015-04-08 8:28 GMT+08:00 Brendan Dolan-Gavitt<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> Could you be a little more descriptive about<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> how it failed?<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> Segfault? Error message? Incorrect output?<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> -Brendan<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> On Tue, Apr 7, 2015 at 8:27 PM, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>> wrote:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> i tried taint2 too,it failed.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> 2015-04-07 5:20 GMT+08:00 Leek, Timothy -<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> 0559 - MITLL<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> <<a href="mailto:tleek@ll.mit.edu" target="_blank">tleek@ll.mit.edu</a>>:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Also note that the “taint” plugin is<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> somewhat defunct.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> “taint2” is the one we are actively using<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> and developing.<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Tim Leek<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Technical Staff<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Cyber System Assessments<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> MIT Lincoln Laboratory<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> <a href="tel:781-981-2975" value="+17819812975" target="_blank">781-981-2975</a><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> From: Brendan Dolan-Gavitt<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> <<a href="mailto:brendandg@gatech.edu" target="_blank">brendandg@gatech.edu</a>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Date: Monday, April 6, 2015 at 5:18 PM<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> To: xiaojuan Li <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Cc: "<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>"<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> <<a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Subject: Re: [panda-users] taint<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> segmentation fault<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> Could you run that under gdb and provide us<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> with a backtrace<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> when it crashes?<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> -Brendan<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> On Sunday, April 5, 2015, xiaojuan Li<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> <<a href="mailto:xiaotan6666@gmail.com" target="_blank">xiaotan6666@gmail.com</a>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>> wrote:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> Hi,<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> excuse me,i have a question about taint<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> plugin:(stringsearch:name=***;taint:tainted_instructions=1)<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> when I started it showed success:<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> but when it finished search,it showd<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> "uninit taint plugin<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> segementation fault"<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> how can I fix it?<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> Thanks a lot!<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> _______________________________________________<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> panda-users mailing list<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> <a href="mailto:panda-users@mit.edu" target="_blank">panda-users@mit.edu</a><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>> <a href="http://mailman.mit.edu/mailman/listinfo/panda-users" target="_blank">http://mailman.mit.edu/mailman/listinfo/panda-users</a><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>><br>
>>>>>>>>>>>>>>>>> >>>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>><br>
>>>>>>>>>>>>>>>>> >>>>> --<br>
>>>>>>>>>>>>>>>>> >>>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>><br>
>>>>>>>>>>>>>>>>> >>>> --<br>
>>>>>>>>>>>>>>>>> >>>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>><br>
>>>>>>>>>>>>>>>>> >>> --<br>
>>>>>>>>>>>>>>>>> >>> wait and hope~~<br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> >><br>
>>>>>>>>>>>>>>>>> ><br>
>>>>>>>>>>>>>>>>> ><br>
>>>>>>>>>>>>>>>>> ><br>
>>>>>>>>>>>>>>>>> > --<br>
>>>>>>>>>>>>>>>>> > wait and hope~~<br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>><br>
>>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>><br>
>>>>>>>>>>>>> --<br>
>>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>>><br>
>>>>>>>>>>>><br>
>>>>>>>>>>>><br>
>>>>>>>>>>>><br>
>>>>>>>>>>>> --<br>
>>>>>>>>>>>> wait and hope~~<br>
>>>>>>>>>>><br>
>>>>>>>>>>><br>
>>>>>>>>>><br>
>>>>>>>>>><br>
>>>>>>>>>><br>
>>>>>>>>>> --<br>
>>>>>>>>>> wait and hope~~<br>
>>>>>>>>><br>
>>>>>>>>><br>
>>>>>>>><br>
>>>>>>>><br>
>>>>>>>><br>
>>>>>>>> --<br>
>>>>>>>> wait and hope~~<br>
>>>>>>><br>
>>>>>>><br>
>>>>>><br>
>>>>>><br>
>>>>>><br>
>>>>>> --<br>
>>>>>> wait and hope~~<br>
>>>>><br>
>>>>><br>
>>>><br>
>>>><br>
>>>><br>
>>>> --<br>
>>>> wait and hope~~<br>
>>><br>
>>><br>
>><br>
>><br>
>><br>
>> --<br>
>> wait and hope~~<br>
><br>
><br>
><br>
><br>
> --<br>
> wait and hope~~<br>
</div></div></blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div><br></div>
</div></div></blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div></div></div><span><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div></div></div><span class="HOEnZb"><font color="#888888"><br><br clear="all"><br>-- <br><div><div dir="ltr">wait and hope~~</div></div>
</font></span></div>
</blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr">wait and hope~~</div></div>
</div>