Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
octopus — WebAssemblyモジュール(wasm)およびブロックチェーンスマートコントラクト(BTC/ETH/NEO/EOS)向けのセキュリティ分析ツール | Kitploit
ツール/GitHubGitHub/fuzzinglabs/octopus
静的分析動的分析 (サンドボックス)リバースエンジニアリングファジングバイナリ解析Archived
GitHubfuzzinglabs/octopus

octopus

WebAssemblyモジュール(wasm)およびブロックチェーンスマートコントラクト(BTC/ETH/NEO/EOS)向けのセキュリティ分析ツール

リポジトリを見る
49490172年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
ウェブサイト
共有

Octopus

made-with-python MIT license

このプロジェクトをスポンサーしてくれたQuoScientに心から感謝します。

Octopusは、WebAssemblyモジュールとブロックチェーンスマートコントラクトのためのセキュリティ分析フレームワークです。

Octopusの目的は、クローズドソースのWebAssemblyモジュールやスマートコントラクトのバイトコードを簡単に分析し、その内部動作をより深く理解する方法を提供することです。

機能

  • エクスプローラ: ブロックチェーンプラットフォームと通信するためのOctopus JSON-RPCクライアント実装
  • 逆アセンブラ: Octopusはバイトコードをアセンブリ表現に変換できます
  • 制御フロー分析: Octopusは制御フローグラフ(CFG)を生成できます
  • 呼び出しフロー分析: Octopusは呼び出しフローグラフ(関数レベル)を生成できます
  • IR変換(SSA): Octopusはアセンブリを静的単一代入(SSA)表現に簡略化できます
  • シンボリック実行: Octopusはシンボリック実行を使用してプログラム内の新しいパスを見つけます

プラットフォーム / アーキテクチャ

Octopusは以下の種類のプログラム/スマートコントラクトをサポートしています:

  • WebAssembly module (WASM)
  • Bitcoin script (BTC script)
  • Ethereum smart contracts (EVM bytecode & Ewasm)
  • EOS smart contracts (WASM)
  • NEO smart contracts (AVM bytecode)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
エクスプローラ✔️✔️✔️✔️✔️⭕
逆アセンブラ✔️✔️✔️✔️✔️✔️
制御フロー分析✖️✔️✔️✔️✔️✔️
呼び出しフロー分析✖️➕✔️✔️➕✔️
IR変換(SSA)✖️✔️➕➕✖️✔️
シンボリック実行✖️➕➕➕✖️➕
  • PyPI パッケージ ✔️
  • Docker ✔️

✔️ 完了 / ➕ 作業中 / ✖️ 未対応 / ⭕ 該当なし

必要条件

OctopusはLinux(理想的にはUbuntu 16.04)でサポートされており、Python >=3.5(理想的には3.6)が必要です。

依存関係:

  • グラフ生成: graphviz
  • エクスプローラ: requests
  • シンボリック実行: z3-solver
  • Wasm: wasm

クイックスタート

  • システムの依存関係をインストール```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- Octopus をインストール:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

または```

but prefer the first way to install if possible

pip3 install octopus

- テストを実行```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

Dockerコンテナ

ツールセットを提供するDockerコンテナはdocker hubで利用可能です。 ターミナルで、以下のコマンドを実行してください:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## コマンドラインツール

* WebAssembly: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* Ethereum (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## APIを用いた詳細な例

<details><summary>WebAssembly</summary>
<p>

#### 逆アセンブラ

Wasmモジュールの逆アセンブル:```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

wasmバイトコードの逆アセンブル:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)

# show analyzer attributes
print(analyzer.func_prototypes)
# [('putc_js', 'i32', ''),
#  ('__syscall0', 'i32', 'i32'),
#  ('__syscall3', 'i32 i32 i32 i32', 'i32'),
#  ('__syscall1', 'i32 i32', 'i32'),
#  ('__syscall5', 'i32 i32 i32 i32 i32 i32', 'i32'),
#  ('__syscall4', 'i32 i32 i32 i32 i32', 'i32'),
#  ('$func6', '', ''),
#  ('main', '', 'i32'),
#  ('writev_c', 'i32 i32 i32', 'i32'),
#  ('$func9', '', 'i32'),
#  ('$func10', 'i32', 'i32'),
#  ('$func11', 'i32', 'i32'),
#  ('$func12', 'i32', ''),
#  ('$func13', 'i32', 'i32'),
#  ('$func14', 'i32 i32 i32 i32', 'i32'),
#  ('$func15', 'i32 i32', 'i32'),
#  ('$func16', 'i32 i32', 'i32'),
#  ('$func17', 'i32', 'i32'),
#  ('$func18', 'i32', 'i32'),
#  ('$func19', 'i32', 'i32'),
#  ('$func20', 'i32 i32 i32', 'i32'),
#  ('$func21', 'i32 i32 i32', 'i32'),
#  ('$func22', 'i32 i64 i32', 'i64'),
#  ('$func23', 'i32 i32 i32', 'i32'),
#  ('$func24', 'i32', 'i32'),
#  ('$func25', 'i32 i32 i32 i32', '')]
print()
print(analyzer.contains_emscripten_syscalls())
#[('__syscall0', 'restart_syscall'),
# ('__syscall3', 'read'),
# ('__syscall1', 'exit'),
# ('__syscall5', 'open'),
# ('__syscall4', 'write')]

制御フロー分析```python

from octopus.arch.wasm.cfg import WasmCFG

complete wasm module

file_name = "examples/wasm/samples/fib.wasm"

read file

with open(file_name, 'rb') as f: raw = f.read()

create the cfg

cfg = WasmCFG(raw)

ツールをダウンロード