Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
octopus — أداة تحليل أمان لوحدات WebAssembly (wasm) وعقود البلوكشين الذكية (BTC/ETH/NEO/EOS) | Kitploit
أدوات/GitHubGitHub/fuzzinglabs/octopus
التحليل الثابتالتحليل الديناميكي (عزل)الهندسة العكسيةالاختبار العشوائيتحليل الملفات الثنائيةArchived
GitHubfuzzinglabs/octopus

octopus

أداة تحليل أمان لوحدات WebAssembly (wasm) وعقود البلوكشين الذكية (BTC/ETH/NEO/EOS)

عرض المستودع
4949017منذ 2 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
الموقع الإلكتروني
مشاركة

أخطبوط

made-with-python MIT license

شكر جزيل لـ QuoScient لرعايتها لهذا المشروع.

أخطبوط هو إطار تحليل أمني لوحدات WebAssembly والعقود الذكية على سلاسل الكتل (Blockchain).

الهدف من أخطبوط هو توفير طريقة سهلة لتحليل وحدات WebAssembly مغلقة المصدر والبايت كود للعقود الذكية لفهم سلوكياتها الداخلية بشكل أعمق.

الميزات

  • المتصفح (Explorer): تطبيق عميل JSON-RPC في أخطبوط للتواصل مع منصات سلسلة الكتل
  • مفكك التجميع (Disassembler): يمكن لأخطبوط ترجمة البايت كود إلى تمثيل تجميعي
  • تحليل تدفق التحكم (Control Flow Analysis): يمكن لأخطبوط إنشاء رسم بياني لتدفق التحكم (CFG)
  • تحليل تدفق الاستدعاءات (Call Flow Analysis): يمكن لأخطبوط إنشاء رسم بياني لتدفق الاستدعاءات (على مستوى الدوال)
  • تحويل إلى تمثيل وسيط SSA: يمكن لأخطبوط تبسيط التجميع إلى تمثيل SSA
  • التنفيذ الرمزي (Symbolic Execution): يستخدم أخطبوط التنفيذ الرمزي لإيجاد مسارات جديدة داخل البرنامج

المنصات / المعماريات

يدعم أخطبوط الأنواع التالية من البرامج/العقود الذكية:

  • وحدات WebAssembly (WASM)
  • سكريبت بيتكوين (BTC script)
  • عقود إيثيريوم الذكية (EVM bytecode و Ewasm)
  • عقود EOS الذكية (WASM)
  • عقود NEO الذكية (AVM bytecode)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
المتصفح✔️✔️✔️✔️✔️⭕
مفكك التجميع✔️✔️✔️✔️✔️✔️
تحليل تدفق التحكم✖️✔️✔️✔️✔️✔️
تحليل تدفق الاستدعاءات✖️➕✔️✔️➕✔️
تحويل SSA✖️✔️➕➕✖️✔️
التنفيذ الرمزي✖️➕➕➕✖️➕
  • حزمة PyPI ✔️
  • Docker ✔️

✔️ مكتمل / ➕ قيد العمل / ✖️ مستقبلي / ⭕ غير قابل للتطبيق

المتطلبات

أخطبوط مدعوم على لينكس (يفضل Ubuntu 16.04) ويتطلب Python >=3.5 (يفضل 3.6).

التبعيات:

  • توليد الرسوم البيانية: graphviz
  • المتصفح: requests
  • التنفيذ الرمزي: z3-solver
  • Wasm: wasm

البدء السريع

  • تثبيت تبعيات النظام```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- تثبيت Octopus:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

أو```

but prefer the first way to install if possible

pip3 install octopus

- تشغيل الاختبارات```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

حاوية Docker

حاوية Docker توفر مجموعة الأدوات متاحة على docker hub. في الطرفية، قم بتشغيل الأوامر التالية:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## أدوات سطر الأوامر

* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## أمثلة متعمقة باستخدام APIs

<details><summary>WebAssembly</summary>
<p>

#### مفكك الشفرة

تفكيك وحدة Wasm:```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

تفكيك bytecode wasm:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)
تنزيل الأداة