[panda-users] taint analysis for android core

Brendan Dolan-Gavitt brendandg at nyu.edu
Wed Dec 13 13:27:11 EST 2017


To elaborate a little more: the main issue is QEMU yet again changing
things up in how you write peripherals. So most of the Android emulator
peripherals that Josh Hodosh painstakingly ported (over ~6 months if I
remember) to QEMU 1.1 for PANDA1 now have to be ported again :(

In the past, I have been able to get Android images that were specifically
ported to a platform QEMU supports natively (such as the vexpress-a9)
running in PANDA. And going even further, I think there are now x86 Android
builds, which presumably would work in QEMU out of the box. I don't know if
either of those are similar enough to the Android that runs on modern
phones for your purposes, but it seems like it's worth a shot.

Best,
Brendan

On Wed, Dec 13, 2017 at 9:03 AM, Leek, Timothy - 0559 - MITLL <
tleek at ll.mit.edu> wrote:

> Hi Manolis.  If you want to use taint, you should definitely use taint2
> from PANDA2.  That’s the best option in terms of speed and correctness.  I
> don’t know about getting Android working on PANDA2.  We haven’t tried to
> port any of the required code over and the guy who originally got that
> stuff working has left MIT. Certainly, you wouldn’t be able to do much with
> graphics even if you got it up and running.
>
>
>
>
> --
>
> Tim Leek
>
> Technical Staff
>
> Cyber System Assessments
>
> MIT Lincoln Laboratory
>
> 781-981-2975 <(781)%20981-2975>
>
>
>
>
>
> *From: *<panda-users-bounces at mit.edu> on behalf of Manolis
> Stamatogiannakis <mstamat at gmail.com>
> *Date: *Tuesday, December 12, 2017 at 8:24 PM
> *To: *"panda-users at mit.edu" <panda-users at mit.edu>
> *Subject: *[panda-users] taint analysis for android core
>
>
>
> I plan to use taint analysis for analyzing the android core (i.e.
> non-application code).
>
>
>
> Would PANDA2/taint2 be a suitable platform this application?
>
>
>
> I know that some android support code was left back in PANDA1. Would the
> android core run without this code so I can use PANDA2? I don't really
> about having graphics or a functional UI.
>
>
>
> Thanks in advance,
>
> Manolis
>
> _______________________________________________
> panda-users mailing list
> panda-users at mit.edu
> http://mailman.mit.edu/mailman/listinfo/panda-users
>
>


-- 
Brendan Dolan-Gavitt
Assistant Professor, Department of Computer Science and Engineering
NYU Tandon School of Engineering
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.mit.edu/pipermail/panda-users/attachments/20171213/c7997c34/attachment.html


More information about the panda-users mailing list