Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
octopus — Strumento di analisi della sicurezza per moduli WebAssembly (wasm) e Smart Contract Blockchain (BTC/ETH/NEO/EOS) | Kitploit
Strumenti/GitHubGitHub/fuzzinglabs/octopus
Analisi StaticaAnalisi Dinamica (Sandboxing)Reverse EngineeringFuzzingAnalisi di BinariArchived
GitHubfuzzinglabs/octopus

octopus

Strumento di analisi della sicurezza per moduli WebAssembly (wasm) e Smart Contract Blockchain (BTC/ETH/NEO/EOS)

Vedi Repository
49490162 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Sito web
Condividi

Octopus

realizzato-con-python Licenza MIT

Un enorme ringraziamento a QuoScient per aver sponsorizzato questo progetto.

Octopus è un framework di analisi della sicurezza per moduli WebAssembly e Smart Contract Blockchain.

Lo scopo di Octopus è quello di fornire un modo semplice per analizzare moduli WebAssembly chiusi e bytecode di smart contract, al fine di comprenderne più a fondo i comportamenti interni.

Funzionalità

  • Explorer: implementazione client JSON-RPC di Octopus per comunicare con piattaforme blockchain
  • Disassembler: Octopus può tradurre il bytecode in rappresentazione assembly
  • Analisi del Flusso di Controllo: Octopus può generare un grafo di flusso di controllo (CFG)
  • Analisi del Flusso di Chiamata: Octopus può generare un grafo di flusso di chiamata (a livello di funzione)
  • Conversione in IR (SSA): Octopus può semplificare l'assembly in rappresentazione Static Single Assignment (SSA)
  • Esecuzione Simbolica: Octopus utilizza l'esecuzione simbolica per trovare nuovi percorsi in un programma

Piattaforme / Architetture

Octopus supporta i seguenti tipi di programmi/smart contract:

  • Modulo WebAssembly (WASM)
  • Script Bitcoin (script BTC)
  • Smart contract Ethereum (bytecode EVM e Ewasm)
  • Smart contract EOS (WASM)
  • Smart contract NEO (bytecode AVM)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
Explorer✔️✔️✔️✔️✔️⭕
Disassembler✔️✔️✔️✔️✔️✔️
Analisi del Flusso di Controllo✖️✔️✔️✔️✔️✔️
Analisi del Flusso di Chiamata✖️➕✔️✔️➕✔️
Conversione in IR (SSA)✖️✔️➕➕✖️✔️
Esecuzione Simbolica✖️➕➕➕✖️➕
  • Pacchetto PyPI ✔️
  • Docker ✔️

✔️ FATTO / ➕ IN CORSO / ✖️ DA FARE / ⭕ N/D

Requisiti

Octopus è supportato su Linux (idealmente Ubuntu 16.04) e richiede Python >=3.5 (idealmente 3.6).

Dipendenze:

  • Generazione di grafici: graphviz
  • Explorer: requests
  • Esecuzione simbolica: z3-solver
  • Wasm: wasm

Avvio Rapido

  • Installa le dipendenze di sistema```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- Installa Octopus:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

o```

but prefer the first way to install if possible

pip3 install octopus

- Esegui i test```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

Docker container

Un contenitore docker che fornisce il set di strumenti è disponibile su docker hub. In un terminale, esegui i seguenti comandi:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## Strumenti da riga di comando

* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## Esempi approfonditi con le API

<details><summary>WebAssembly</summary>
<p>

#### Disassemblatore

Disassemblaggio di un modulo Wasm:```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

Disassemblaggio del bytecode wasm:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)
Scarica lo strumento