
أداة تحليل أمان لوحدات WebAssembly (wasm) وعقود البلوكشين الذكية (BTC/ETH/NEO/EOS)
شكر جزيل لـ QuoScient لرعايتها لهذا المشروع.
أخطبوط هو إطار تحليل أمني لوحدات WebAssembly والعقود الذكية على سلاسل الكتل (Blockchain).
الهدف من أخطبوط هو توفير طريقة سهلة لتحليل وحدات WebAssembly مغلقة المصدر والبايت كود للعقود الذكية لفهم سلوكياتها الداخلية بشكل أعمق.
يدعم أخطبوط الأنواع التالية من البرامج/العقود الذكية:
| BTC | ETH (EVM) | ETH (WASM) | EOS | NEO | WASM | ||
|---|---|---|---|---|---|---|---|
| المتصفح | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ⭕ | |
| مفكك التجميع | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| تحليل تدفق التحكم | ✖️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
| تحليل تدفق الاستدعاءات | ✖️ | ➕ | ✔️ | ✔️ | ➕ | ✔️ | |
| تحويل SSA | ✖️ | ✔️ | ➕ | ➕ | ✖️ | ✔️ | |
| التنفيذ الرمزي | ✖️ | ➕ | ➕ | ➕ | ✖️ | ➕ |
✔️ مكتمل / ➕ قيد العمل / ✖️ مستقبلي / ⭕ غير قابل للتطبيق
أخطبوط مدعوم على لينكس (يفضل Ubuntu 16.04) ويتطلب Python >=3.5 (يفضل 3.6).
التبعيات:
sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y
- تثبيت Octopus:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus
# Install Octopus library/CLI and its dependencies
python3 setup.py install
أو```
pip3 install octopus
- تشغيل الاختبارات```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh
# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh
حاوية Docker توفر مجموعة الأدوات متاحة على docker hub. في الطرفية، قم بتشغيل الأوامر التالية:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode
## أدوات سطر الأوامر
* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)
## أمثلة متعمقة باستخدام APIs
<details><summary>WebAssembly</summary>
<p>
#### مفكك الشفرة
تفكيك وحدة Wasm:```python
from octopus.arch.wasm.disassembler import WasmDisassembler
FILE = "examples/wasm/samples/helloworld.wasm"
with open(FILE, 'rb') as f:
module_bytecode = f.read()
disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]
print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end
تفكيك bytecode wasm:```python from octopus.arch.wasm.disassembler import WasmDisassembler
bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'
disasm = WasmDisassembler(bytecode)
print(disasm.disassemble())
#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))
#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))
#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer
FILE = "examples/wasm/samples/hello_wasm_studio.wasm"
with open(FILE, 'rb') as f:
module_bytecode = f.read()
# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)