Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
octopus — WebAssembly 모듈(wasm) 및 블록체인 스마트 계약(BTC/ETH/NEO/EOS)을 위한 보안 분석 도구 | Kitploit
도구/GitHubGitHub/fuzzinglabs/octopus
Static AnalysisDynamic Analysis (Sandboxing)Reverse EngineeringFuzzingBinary AnalysisArchived
GitHubfuzzinglabs/octopus

octopus

WebAssembly 모듈(wasm) 및 블록체인 스마트 계약(BTC/ETH/NEO/EOS)을 위한 보안 분석 도구

저장소 보기
49490162년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
웹사이트
공유

Octopus

made-with-python MIT license

이 프로젝트를 후원해 주신 QuoScient에 진심으로 감사드립니다.

Octopus는 WebAssembly 모듈과 블록체인 스마트 계약을 위한 보안 분석 프레임워크입니다.

Octopus의 목적은 폐쇄 소스 WebAssembly 모듈과 스마트 계약 바이트코드를 분석하여 내부 동작을 더 깊이 이해할 수 있는 쉬운 방법을 제공하는 것입니다.

기능

  • 탐색기(Explorer): 블록체인 플랫폼과 통신하기 위한 Octopus JSON-RPC 클라이언트 구현
  • 디스어셈블러(Disassembler): Octopus는 바이트코드를 어셈블리 표현으로 변환할 수 있습니다
  • 제어 흐름 분석(Control Flow Analysis): Octopus는 제어 흐름 그래프(CFG)를 생성할 수 있습니다
  • 호출 흐름 분석(Call Flow Analysis): Octopus는 호출 흐름 그래프(함수 수준)를 생성할 수 있습니다
  • IR 변환(SSA): Octopus는 어셈블리를 정적 단일 할당(SSA) 표현으로 단순화할 수 있습니다
  • 기호 실행(Symbolic Execution): Octopus는 기호 실행을 사용하여 프로그램에서 새로운 경로를 찾습니다

플랫폼 / 아키텍처

Octopus는 다음 유형의 프로그램/스마트 계약을 지원합니다:

  • WebAssembly 모듈 (WASM)
  • 비트코인 스크립트 (BTC 스크립트)
  • 이더리움 스마트 계약 (EVM 바이트코드 및 Ewasm)
  • EOS 스마트 계약 (WASM)
  • NEO 스마트 계약 (AVM 바이트코드)
BTCETH (EVM)ETH (WASM)EOSNEOWASM
탐색기(Explorer)✔️✔️✔️✔️✔️⭕
디스어셈블러(Disassembler)✔️✔️✔️✔️✔️✔️
제어 흐름 분석(Control Flow Analysis)✖️✔️✔️✔️✔️✔️
호출 흐름 분석(Call Flow Analysis)✖️➕✔️✔️➕✔️
IR 변환(SSA)✖️✔️➕➕✖️✔️
기호 실행(Symbolic Execution)✖️➕➕➕✖️➕
  • PyPI 패키지 ✔️
  • Docker ✔️

✔️ 완료 / ➕ 진행 중 / ✖️ 예정 / ⭕ 해당 없음

요구 사항

Octopus는 Linux(Ubuntu 16.04 권장)에서 지원되며 Python >=3.5(3.6 권장)가 필요합니다.

종속성:

  • 그래프 생성: graphviz
  • 탐색기: requests
  • 기호 실행: z3-solver
  • Wasm: wasm

빠른 시작

  • 시스템 종속성 설치```

Install system dependencies

sudo apt-get update && sudo apt-get install python-pip graphviz xdg-utils -y

- Octopus 설치:```
# Download Octopus
git clone https://github.com/pventuzelo/octopus
cd octopus

# Install Octopus library/CLI and its dependencies
python3 setup.py install

또는```

but prefer the first way to install if possible

pip3 install octopus

- 테스트 실행```
# Run tests for all platforms (disassembly, CFG, ...)
./run_tests.sh
# Run tests that require internet access (explorer tests)
./run_explorer_tests.sh

# Run tests for only one platforms
# {btc, eth, eos, neo, wasm}_run_tests.sh
cd octopus/tests/
./wasm_run_tests.sh

도커 컨테이너

도구 세트를 제공하는 docker 컨테이너는 docker hub에서 사용할 수 있습니다. 터미널에서 다음 명령을 실행하십시오:``` docker pull smartbugs/octopus docker run -it smartbugs/octopus cd octopus python3 octopus_eth_evm.py -s -f examples/ETH/evm_bytecode/61EDCDf5bb737ADffE5043706e7C5bb1f1a56eEA.bytecode

## 명령줄 도구

* 웹어셈블리: [octopus_wasm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_wasm.py)
* 이더리움 (EVM): [octopus_eth_evm.py](https://github.com/fuzzinglabs/octopus/blob/master/octopus_eth_evm.py)


## API를 사용한 심층 예제

<details><summary>웹어셈블리</summary>
<p>

#### 디스어셈블러

Wasm 모듈의 디스어셈블리:```python
from octopus.arch.wasm.disassembler import WasmDisassembler

FILE = "examples/wasm/samples/helloworld.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

disasm = WasmDisassembler()
# return list of functions instructions (list)
print(disasm.disassemble_module(module_bytecode))
#[[<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904278>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904f60>,<octopus.arch.wasm.instruction.WasmInstruction at 0x7f85e4904ef0>]]

print()
# return text of functions code
print(disasm.disassemble_module(module_bytecode, r_format='text'))
# func 0
# i32.const 0
# call 0
# end

wasm 바이트코드의 역어셈블리:```python from octopus.arch.wasm.disassembler import WasmDisassembler

bytecode in WebAssembly is the function code (i.e. function body)

bytecode = b'\x02\x7fA\x18\x10\x1cA\x00\x0f\x0b'

create a WasmDisassembler object

disasm = WasmDisassembler(bytecode)

disassemble bytecode into a list of WasmInstruction

attributes r_format='list' by default

print(disasm.disassemble())

#[<octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904eb8>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>] print() print(disasm.disassemble(r_format='reverse'))

#{0: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4901048>, 1: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904240>, 2: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904f60>, 3: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904ef0>, 4: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904278>, 5: <octopus.arch.wasm.instruction.WasmInstruction object at 0x7f85e4904390>} print() print(disasm.disassemble(r_format='text'))

block -1

i32.const 24

call 28

i32.const 0

return

end

#### ModuleAnalyzer```python
from octopus.arch.wasm.analyzer import WasmModuleAnalyzer

FILE = "examples/wasm/samples/hello_wasm_studio.wasm"

with open(FILE, 'rb') as f:
    module_bytecode = f.read()

# return list of functions instructions (list)
# attributes analysis=True by default
analyzer = WasmModuleAnalyzer(module_bytecode)

# show analyzer attributes
print(analyzer.func_prototypes)
# [('putc_js', 'i32', ''),
#  ('__syscall0', 'i32', 'i32'),
#  ('__syscall3', 'i32 i32 i32 i32', 'i32'),
#  ('__syscall1', 'i32 i32', 'i32'),
#  ('__syscall5', 'i32 i32 i32 i32 i32 i32', 'i32'),
#  ('__syscall4', 'i32 i32 i32 i32 i32', 'i32'),
#  ('$func6', '', ''),
#  ('main', '', 'i32'),
#  ('writev_c', 'i32 i32 i32', 'i32'),
#  ('$func9', '', 'i32'),
#  ('$func10', 'i32', 'i32'),
#  ('$func11', 'i32', 'i32'),
#  ('$func12', 'i32', ''),
#  ('$func13', 'i32', 'i32'),
#  ('$func14', 'i32 i32 i32 i32', 'i32'),
#  ('$func15', 'i32 i32', 'i32'),
#  ('$func16', 'i32 i32', 'i32'),
#  ('$func17', 'i32', 'i32'),
#  ('$func18', 'i32', 'i32'),
#  ('$func19', 'i32', 'i32'),
#  ('$func20', 'i32 i32 i32', 'i32'),
#  ('$func21', 'i32 i32 i32', 'i32'),
#  ('$func22', 'i32 i64 i32', 'i64'),
#  ('$func23', 'i32 i32 i32', 'i32'),
#  ('$func24', 'i32', 'i32'),
#  ('$func25', 'i32 i32 i32 i32', '')]
print()
print(analyzer.contains_emscripten_syscalls())
#[('__syscall0', 'restart_syscall'),
# ('__syscall3', 'read'),
# ('__syscall1', 'exit'),
# ('__syscall5', 'open'),
# ('__syscall4', 'write')]

제어 흐름 분석```python

from octopus.arch.wasm.cfg import WasmCFG

complete wasm module

file_name = "examples/wasm/samples/fib.wasm"

read file

with open(file_name, 'rb') as f: raw = f.read()

create the cfg

cfg = WasmCFG(raw)

도구 다운로드