Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
octopus — Sicherheitsanalyse-Tool für WebAssembly-Module (wasm) und Blockchain-Smart-Contracts (BTC/ETH/NEO/EOS) | Kitploit
Tools/GitHubGitHub/fuzzinglabs/octopus
Statische AnalyseDynamische Analyse (Sandboxing)Reverse EngineeringFuzzingBinäranalyseArchived
GitHubfuzzinglabs/octopus

octopus

Sicherheitsanalyse-Tool für WebAssembly-Module (wasm) und Blockchain-Smart-Contracts (BTC/ETH/NEO/EOS)

Repository anzeigen
4949016vor 2 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Webseite
Teilen

Octopus

made-with-python MIT license

Großes Dankeschön an QuoScient für die Finanzierung dieses Projekts.

Octopus ist ein Sicherheitsanalyse-Framework für WebAssembly-Module und Blockchain-Smart-Contracts.

Der Zweck von Octopus ist es, eine einfache Möglichkeit zur Analyse von Closed-Source-WebAssembly-Modulen und Smart-Contract-Bytecode zu bieten, um deren internes Verhalten besser zu verstehen.

Funktionen

  • Explorer: Octopus JSON-RPC-Client-Implementierung zur Kommunikation mit Blockchain-Plattformen
  • Disassembler: Octopus kann Bytecode in eine Assembly-Darstellung übersetzen
  • Kontrollflussanalyse: Octopus kann einen Kontrollflussgraphen (CFG) erzeugen
  • Aufrufflussanalyse: Octopus kann einen Aufrufflussgraphen (auf Funktionsebene) erzeugen
  • IR-Konvertierung (SSA): Octopus kann Assembly in eine Static-Single-Assignment-Darstellung (SSA) vereinfachen
  • Symbolische Ausführung: Octopus verwendet symbolische Ausführung, um neue Pfade in einem Programm zu finden

Plattformen / Architekturen

Octopus unterstützt die folgenden Arten von Programmen/Smart-Contracts:

  • WebAssembly-Modul (WASM)
  • Bitcoin-Skript (BTC-Skript)
  • Ethereum-Smart-Contracts (EVM-Bytecode & Ewasm)
  • EOS-Smart-Contracts (WASM)
  • NEO-Smart-Contracts (AVM-Bytecode)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
Explorer✔️✔️✔️✔️✔️⭕
Disassembler✔️✔️✔️✔️✔️✔️
Kontrollflussanalyse✖️✔️✔️✔️✔️✔️
Aufrufflussanalyse✖️➕✔️✔️➕✔️
IR-Konvertierung (SSA)✖️✔️➕➕✖️✔️
Symbolische Ausführung✖️➕➕➕✖️➕
  • PyPI package ✔️
  • Docker ✔️

✔️ DONE / ➕ WIP / ✖️ TODO / ⭕ N/A

Voraussetzungen

Octopus wird unter Linux (idealerweise Ubuntu 16.04) unterstützt und benötigt Python >=3.5 (idealerweise 3.6).

Abhängigkeiten:

  • Grapherzeugung: graphviz
  • Explorer: requests
  • Symbolische Ausführung: z3-solver
  • Wasm: wasm

Kurzanleitung

  • Systemabhängigkeiten installieren```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- Installiere Octopus:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

oder```

but prefer the first way to install if possible

pip3 install octopus

- Tests ausführen```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

Docker-Container

Ein Docker-Container, der den Werkzeugsatz bereitstellt, ist unter Docker Hub verfügbar. Führen Sie in einem Terminal die folgenden Befehle aus:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## Kommandozeilenwerkzeuge

* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## Tiefgehende Beispiele mit APIs

<details><summary>WebAssembly</summary>
<p>

#### Disassembler

Disassemblierung eines Wasm-Moduls:```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

Disassemblierung des wasm-Bytecodes:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)
Tool herunterladen