Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
seccomp-tools — seccomp 분석을 위한 강력한 도구 제공 | Kitploit
도구/GitHubGitHub/david942j/seccomp-tools
Dynamic Analysis (Sandboxing)Reverse EngineeringCTFBinary AnalysisLearning & Education
GitHubdavid942j/seccomp-tools

seccomp-tools

seccomp 분석을 위한 강력한 도구 제공

저장소 보기
1.1k73376일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Downloads

Gem Version Build Status Maintainability Code Coverage Inline docs Yard Docs MIT License

Seccomp Tools

seccomp 분석을 위한 강력한 도구입니다.

이 프로젝트는 주로(그러나 전적으로는 아닌) CTF pwn 챌린지에서 seccomp 샌드박스를 분석하는 데 목적을 둡니다. 일부 기능은 CTF에 특화되어 있지만, 실제 환경의 seccomp 필터를 분석하는 데에도 그만큼 유용합니다.

기능

  • Dump - 실행 파일에서 seccomp BPF를 자동으로 덤프합니다.
  • Disasm - seccomp BPF를 사람이 읽을 수 있는 형식으로 변환합니다.
    • 간단한 역컴파일 지원.
    • 가능한 경우 syscall 이름과 인자 표시.
    • 컬러풀!
  • Asm - seccomp 규칙 작성이 코드 작성만큼 쉬워집니다.
  • Emu - seccomp 규칙을 에뮬레이션합니다.
  • Explain - 필터를 동작별 정책(어떤 syscall이 허용/차단되는지, 그리고 언제)으로 요약합니다.
  • Audit - 필터에서 취약점과 탈출 경로(누락된 arch/x32 가드, 위험한 syscall 등)를 스캔합니다.
  • 다중 아키텍처 지원.

설치

RubyGems.org에서 이용 가능합니다!``` $ gem install seccomp-tools

컴파일이 실패하면 다음을 시도하세요:```
sudo apt install gcc ruby-dev make

그런 다음 seccomp-tools를 다시 설치합니다.

명령줄 인터페이스

seccomp-tools```bash

$ seccomp-tools --help

Usage: seccomp-tools [--version] [--help] []

List of commands:

asm Seccomp bpf assembler.

audit Assess a seccomp filter for weaknesses and escape routes.

completion Print a shell completion script.

disasm Disassemble seccomp bpf.

dump Automatically dump seccomp bpf from executable(s).

emu Emulate seccomp rules.

explain Summarize a seccomp filter as a per-action policy.

See 'seccomp-tools --help' to read about a specific subcommand.

$ seccomp-tools dump --help

dump - Automatically dump seccomp bpf from executable(s).

NOTE: This command is only available on Linux.

Usage: seccomp-tools dump [EXEC] [options]

-c, --sh-exec Executes the given command (via sh) and dumps its seccomp.

Use this to pass arguments or pipe things to the executable.

e.g. use -c "./bin > /dev/null" to keep the program output out of the result.

Takes precedence over the positional argument.

-l, --limit LIMIT Dump only the first LIMIT installed filters.

Only meaningful when the input is an executable or --pid. Default: 1

An executable is killed once it reaches LIMIT.

-p, --pid PID Dump the seccomp filters installed on an existing process.

You must have CAP_SYS_ADMIN (e.g. be root) to use this option.

-t, --timeout SEC Timeout (seconds) for the execution. Default: no timeout

This option is ignored when --pid is given.

-f, --format FORMAT Output format. FORMAT can only be one of <disasm|raw|inspect>.

Default: disasm

-o, --output FILE Write output to FILE instead of stdout.

If multiple seccomp syscalls have been invoked (see --limit),

results are written to FILE, FILE_1, FILE_2, etc.

For example, with "--output out.bpf" the output files are out.bpf, out_1.bpf, ...

### dump

`ptrace` 시스템 콜을 사용하여 실행 파일에서 seccomp BPF를 덤프합니다.

참고: 대상 실행 파일이 실제로 실행되므로 신뢰할 수 없는 바이너리에는 주의하세요.```bash
$ file spec/binary/twctf-2016-diary
# spec/binary/twctf-2016-diary: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=3648e29153ac0259a0b7c3e25537a5334f50107f, not stripped

$ seccomp-tools dump spec/binary/twctf-2016-diary
#  line  CODE  JT   JF      K
# =================================
#  0000: 0x20 0x00 0x00 0x00000000  A = sys_number
#  0001: 0x15 0x00 0x01 0x00000002  if (A != open) goto 0003
#  0002: 0x06 0x00 0x00 0x00000000  return KILL
#  0003: 0x15 0x00 0x01 0x00000101  if (A != openat) goto 0005
#  0004: 0x06 0x00 0x00 0x00000000  return KILL
#  0005: 0x15 0x00 0x01 0x0000003b  if (A != execve) goto 0007
#  0006: 0x06 0x00 0x00 0x00000000  return KILL
#  0007: 0x15 0x00 0x01 0x00000038  if (A != clone) goto 0009
#  0008: 0x06 0x00 0x00 0x00000000  return KILL
#  0009: 0x15 0x00 0x01 0x00000039  if (A != fork) goto 0011
#  0010: 0x06 0x00 0x00 0x00000000  return KILL
#  0011: 0x15 0x00 0x01 0x0000003a  if (A != vfork) goto 0013
#  0012: 0x06 0x00 0x00 0x00000000  return KILL
#  0013: 0x15 0x00 0x01 0x00000055  if (A != creat) goto 0015
#  0014: 0x06 0x00 0x00 0x00000000  return KILL
#  0015: 0x15 0x00 0x01 0x00000142  if (A != execveat) goto 0017
#  0016: 0x06 0x00 0x00 0x00000000  return KILL
#  0017: 0x06 0x00 0x00 0x7fff0000  return ALLOW

$ seccomp-tools dump spec/binary/twctf-2016-diary -f inspect
# "\x20\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x02\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x01\x01\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x3B\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x38\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x39\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x3A\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x55\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x42\x01\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x06\x00\x00\x00\x00\x00\xFF\x7F"

$ seccomp-tools dump spec/binary/twctf-2016-diary -f raw | xxd
# 00000000: 2000 0000 0000 0000 1500 0001 0200 0000   ...............
# 00000010: 0600 0000 0000 0000 1500 0001 0101 0000  ................
# 00000020: 0600 0000 0000 0000 1500 0001 3b00 0000  ............;...
# 00000030: 0600 0000 0000 0000 1500 0001 3800 0000  ............8...
# 00000040: 0600 0000 0000 0000 1500 0001 3900 0000  ............9...
# 00000050: 0600 0000 0000 0000 1500 0001 3a00 0000  ............:...
# 00000060: 0600 0000 0000 0000 1500 0001 5500 0000  ............U...
# 00000070: 0600 0000 0000 0000 1500 0001 4201 0000  ............B...
# 00000080: 0600 0000 0000 0000 0600 0000 0000 ff7f  ................

disasm

원시 seccomp BPF를 읽을 수 있는 형식으로 역어셈블합니다.```bash $ xxd spec/data/twctf-2016-diary.bpf | head -n 3

00000000: 2000 0000 0000 0000 1500 0001 0200 0000 ...............

00000010: 0600 0000 0000 0000 1500 0001 0101 0000 ................

00000020: 0600 0000 0000 0000 1500 0001 3b00 0000 ............;...

도구 다운로드