Skip to content
KitploitKITPLOIT
OutilsBlog
Log in
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
octopus — Outil d'analyse de sécurité pour module WebAssembly (wasm) et contrats intelligents blockchain (BTC/ETH/NEO/EOS) | Kitploit
Outils/GitHubGitHub/fuzzinglabs/octopus
Analyse StatiqueAnalyse Dynamique (Sandboxing)Rétro-ingénierieFuzzingAnalyse de BinairesArchived
GitHubfuzzinglabs/octopus

octopus

Outil d'analyse de sécurité pour module WebAssembly (wasm) et contrats intelligents blockchain (BTC/ETH/NEO/EOS)

Voir le dépôt
4949017il y a 2 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Site web
Partager

Octopus

made-with-python MIT license

Un grand merci à QuoScient pour avoir sponsorisé ce projet.

Octopus est un framework d'analyse de sécurité pour les modules WebAssembly et les smart contracts de blockchain.

Le but d'Octopus est de fournir un moyen simple d'analyser les modules WebAssembly et le bytecode des smart contracts en source fermée afin de comprendre plus en profondeur leurs comportements internes.

Fonctionnalités

  • Explorer : implémentation d'un client JSON-RPC pour communiquer avec les plateformes blockchain
  • Désassembleur : Octopus peut traduire le bytecode en représentation assembleur
  • Analyse de flux de contrôle : Octopus peut générer un graphe de flux de contrôle (CFG)
  • Analyse de flux d'appels : Octopus peut générer un graphe de flux d'appels (au niveau des fonctions)
  • Conversion en représentation intermédiaire (SSA) : Octopus peut simplifier l'assembleur en une représentation statique à affectation unique (SSA)
  • Exécution symbolique : Octopus utilise l'exécution symbolique pour découvrir de nouveaux chemins dans un programme

Plateformes / Architectures

Octopus prend en charge les types de programmes/smart contracts suivants :

  • Module WebAssembly (WASM)
  • Script Bitcoin (script BTC)
  • Smart contracts Ethereum (bytecode EVM & Ewasm)
  • Smart contracts EOS (WASM)
  • Smart contracts NEO (bytecode AVM)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
Explorer✔️✔️✔️✔️✔️⭕
Désassembleur✔️✔️✔️✔️✔️✔️
Analyse de flux de contrôle✖️✔️✔️✔️✔️✔️
Analyse de flux d'appels✖️➕✔️✔️➕✔️
Conversion en IR (SSA)✖️✔️➕➕✖️✔️
Exécution symbolique✖️➕➕➕✖️➕
  • Package PyPI ✔️
  • Docker ✔️

✔️ FAIT / ➕ EN COURS / ✖️ À FAIRE / ⭕ N/A

Prérequis

Octopus est pris en charge sur Linux (idéalement Ubuntu 16.04) et nécessite Python >=3.5 (idéalement 3.6).

Dépendances :

  • Génération de graphes : graphviz
  • Explorer : requests
  • Exécution symbolique : z3-solver
  • Wasm : wasm

Démarrage rapide

  • Installer les dépendances système```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- Installer Octopus :```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

ou```

but prefer the first way to install if possible

pip3 install octopus

- Exécuter les tests```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

Conteneur Docker

Un conteneur Docker fournissant la boîte à outils est disponible sur docker hub. Dans un terminal, exécutez les commandes suivantes:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## Outils en ligne de commande

* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## Exemples approfondis avec les API

<details><summary>WebAssembly</summary>
<p>

#### Désassembleur

Désassemblage d'un module Wasm :```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

Désassemblage du bytecode wasm:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)
Télécharger l’outil