加入 Empire Hacking Slack
- 讨论与支持
Slither 是一个用 Python3 编写的 Solidity 和 Vyper 静态分析框架。它运行一套漏洞检测器,打印合约细节的可视化信息,并提供 API 以轻松编写自定义分析。Slither 使开发者能够发现漏洞,增强代码理解,并快速原型化自定义分析。
在 Hardhat/Foundry/Dapp/Brownie 应用程序上运行 Slither:```console slither .
如果你的项目有依赖项,这是首选选项,因为 Slither 依赖于底层编译框架来编译源代码。
不过,你也可以在单个不导入依赖的文件上运行 Slither:```console
slither tests/uninitialized.sol
注意 Slither 需要 Python 3.10+。 如果您不打算使用 支持的编译框架,则需要 solc 即 Solidity 编译器;我们推荐使用 solc-select 来方便地在不同 solc 版本间切换。
uv 是一个快速的 Python 包管理器,速度比 pip 快 10 到 100 倍。```console
curl -LsSf https://astral.sh/uv/install.sh | sh
uv tool install slither-analyzer
uvx --from slither-analyzer slither
升级:```console
uv tool upgrade slither-analyzer
python3 -m pip install slither-analyzer
要升级:```console
python3 -m pip install --upgrade slither-analyzer
brew install slither-analyzer
### 使用 Git(开发)```bash
git clone https://github.com/crytic/slither.git && cd slither
# Install as editable for development
uv tool install -e .
# Or use uv run for testing without installation
uv run slither <target>
The -e flag installs in editable mode, meaning changes to the source code are immediately reflected without reinstalling.
使用 eth-security-toolbox Docker 镜像。它在一个镜像中包含了我们所有的安全工具和每个主要版本的 Solidity。/home/share 将被挂载到容器内的 /share。```bash
docker pull trailofbits/eth-security-toolbox
为了在容器中共享一个目录:```bash
docker run -it -v /home/share:/share trailofbits/eth-security-toolbox
$GIT_TAG 替换为实际标签) ```YAML
slither [target] --checklist。slither [target] --checklist --markdown-root https://github.com/ORG/REPO/blob/COMMIT/(替换 ORG、REPO、COMMIT)更多信息,请参见:
human-summary: 输出合约的人类可读摘要inheritance-graph: 将每个合约的继承图导出为 dot 文件contract-summary: 输出合约的摘要loc: 统计源代码文件 (SRC)、依赖文件 (DEP) 和测试文件 (TEST) 中的总代码行数 (LOC)、源代码行数 (SLOC) 和注释行数 (CLOC)。entry-points: 输出合约中所有改变状态的入口点函数及其变量call-graph: 将合约的调用图导出为 dot 文件cfg: 导出每个函数的 CFGfunction-summary: 打印函数摘要vars-and-auth: 打印写入的状态变量和函数的授权信息not-pausable: 打印未使用 whenNotPaused 修饰符的函数.要运行打印机,请使用 --print 和逗号分隔的打印机列表。
参见 打印机文档 获取完整列表。
slither-check-upgradeability: 审查基于 delegatecall 的可升级性slither-prop: 自动生成单元测试和属性slither-flat: 扁平化代码库slither-check-erc: 检查 ERC 合规性slither-read-storage: 从合约读取存储值slither-interface: 为合约生成接口参见 工具文档 获取更多工具。
联系我们 以获取构建自定义工具的帮助。
Slither 内部文档可在 此处 获取。
欢迎访问我们的 Slack 频道 (#ethereum) 以获取使用或扩展 Slither 的帮助。
打印机文档 描述了 Slither 能够为每个合约可视化的信息。
检测器文档 描述了如何编写新的漏洞分析。
API 文档 描述了可用于自定义分析的方法和对象。
SlithIR 文档 描述了 SlithIR 中间表示。
如何排除模拟或测试?
如何解决“未知文件”或编译问题?
slither contract.sol 会失败。
相反,在 contracts/ 的父目录中使用 slither .(当你运行 ls 时应该能看到 contracts/)。
如果你有 node_modules/ 文件夹,它必须与 contracts/ 位于同一目录。为了验证此问题是否与 slither 相关,
运行你正在使用的框架的编译命令,例如 npx hardhat compile。该命令必须成功执行;
否则,slither 的编译引擎 crytic-compile 无法生成 AST。Slither 根据 AGPLv3 许可证授权和分发。如果你正在寻找许可证条款的例外情况,请联系我们。
如果你在学术工作中使用 Slither,考虑申请 Crytic $10k 研究奖。
| 编号 | 检测器 | 检测内容 | 影响 | 置信度 |
|---|
| 1 | abiencoderv2-array | 存储型 abiencoderv2 数组 | 高 | 高 |
| 2 | arbitrary-send-erc20 | transferFrom 使用任意的 from | 高 | 高 |
| 3 | array-by-reference | 按值修改存储数组 | 高 | 高 |
| 4 | encode-packed-collision | ABI encodePacked 碰撞 | 高 | 高 |
| 5 | incorrect-shift | 移位指令中参数顺序错误。 | 高 | 高 |
| 6 | multiple-constructors | 多个构造函数模式 | 高 | 高 |
| 7 | name-reused | 合约名称被重复使用 | 高 | 高 |
| 8 | protected-vars | 检测到未受保护的变量 | 高 | 高 |
| 9 | public-mappings-nested | 具有嵌套变量的公共映射 | 高 | 高 |
| 10 | rtlo | 使用了从右到左覆盖控制字符 | 高 | 高 |
| 11 | shadowing-state | 状态变量遮蔽 | 高 | 高 |
| 12 | suicidal | 允许任何人销毁合约的函数 | 高 | 高 |
| 13 | uninitialized-state | 未初始化的状态变量 | 高 | 高 |
| 14 | uninitialized-storage | 未初始化的存储变量 | 高 | 高 |
| 15 | unprotected-upgrade | 未受保护的可升级合约 | 高 | 高 |
| 16 | arbitrary-send-erc20-permit | transferFrom 使用任意的 from 与 permit | 高 | 中 |
| 17 | arbitrary-send-eth | 将以太币发送到任意目标的函数 | 高 | 中 |
| 18 | controlled-array-length | 受污染的数组长度赋值 | 高 | 中 |
| 19 | controlled-delegatecall | 受控的 delegatecall 目标 | 高 | 中 |
| 20 | delegatecall-loop | 在循环中使用 delegatecall 的可支付函数 | 高 | 中 |
| 21 | incorrect-exp | 不正确的指数运算 | 高 | 中 |
| 22 | incorrect-return | 在汇编模式下错误地使用了 return。 | 高 | 中 |
| 23 | msg-value-loop | 循环中的 msg.value | 高 | 中 |
| 24 | reentrancy-eth | 重入漏洞(窃取以太币) | 高 | 中 |
| 25 | reentrancy-balance | 导致余额检查过时的重入漏洞 | 高 | 中 |
| 26 | return-leave | 使用 return 代替了 leave。 | 高 | 中 |
| 27 | storage-array | 有符号存储整数数组编译器错误 | 高 | 中 |
| 28 | unchecked-transfer | 未检查的代币转账 | 高 | 中 |
| 29 | weak-prng | 弱 PRNG | 高 | 中 |
| 30 | domain-separator-collision | 检测到 ERC20 代币中函数的签名与 EIP-2612 的 DOMAIN_SEPARATOR() 发生碰撞 | 中 | 高 |
| 31 | enum-conversion | 检测危险的枚举类型转换 | 中 | 高 |
| 32 | erc20-interface | 不正确的 ERC20 接口 | 中 | 高 |
| 33 | erc721-interface | 不正确的 ERC721 接口 | 中 | 高 |
| 34 | incorrect-equality | 危险的严格相等比较 | 中 | 高 |
| 35 | locked-ether | 锁定以太币的合约 | 中 | 高 |
| 36 | mapping-deletion | 对包含结构的映射进行删除操作 | 中 | 高 |
| 37 | pyth-deprecated-functions | 检测 Pyth 已弃用的函数 | 中 | 高 |
| 38 | pyth-unchecked-confidence | 检测到未检查 Pyth 价格的置信度级别 | 中 | 高 |
| 39 | pyth-unchecked-publishtime | 检测到未检查 Pyth 价格的 publishTime | 中 | 高 |
| 40 | shadowing-abstract | 来自抽象合约的状态变量遮蔽 | 中 | 高 |
| 41 | tautological-compare | 变量与自身进行比较,根据比较类型总是返回 true 或 false | 中 | 高 |
| 42 | tautology | 永真或矛盾 | 中 | 高 |
| 43 | write-after-write | 未使用的写入 | 中 | 高 |
| 44 | boolean-cst | 布尔常量的误用 | 中 | 中 |
| 45 | chronicle-unchecked-price | 检测到未检查 Chronicle 价格。 | 中 | 中 |
| 46 | constant-function-asm | 使用汇编代码的常量函数 | 中 | 中 |
| 47 | constant-function-state | 改变状态的常量函数 | 中 | 中 |
| 48 | divide-before-multiply | 不精确的算术运算顺序 | 中 | 中 |
| 49 | gelato-unprotected-randomness | 在未受保护的函数中调用 _requestRandomness | 中 | 中 |
| 50 | out-of-order-retryable | 无序的可重试交易 | 中 | 中 |
| 51 | reentrancy-no-eth | 重入漏洞(未窃取以太币) | 中 | 中 |
| 52 | reused-constructor | 重复使用的基构造函数 | 中 | 中 |
| 53 | tx-origin | 危险的 tx.origin 用法 | 中 | 中 |
| 54 | unchecked-lowlevel | 未检查的低级调用 | 中 | 中 |
| 55 | unchecked-send | 未检查的 send | 中 | 中 |
| 56 | uninitialized-local | 未初始化的局部变量 | 中 | 中 |
| 57 | unused-return | 未使用的返回值 | 中 | 中 |
| 58 | chainlink-feed-registry | 检测到使用了 Chainlink feed registry | 低 | 高 |
| 59 | incorrect-modifier | 可能返回默认值的修饰符 | 低 | 高 |
| 60 | optimism-deprecation | 检测到使用了已弃用的 Optimism 预部署或函数。 | 低 | 高 |
| 61 | shadowing-builtin | 内建符号遮蔽 | 低 | 高 |
| 62 | shadowing-local | 局部变量遮蔽 | 低 | 高 |
| 63 | uninitialized-fptr-cst | 构造函数中未初始化的函数指针调用 | 低 | 高 |
| 64 | variable-scope | 在声明之前使用的局部变量 | 低 | 高 |
| 65 | void-cst | 构造函数调用未实现 | 低 | 高 |
| 66 | calls-loop | 循环中的多次调用 | 低 | 中 |
| 67 | events-access | 缺少事件-访问控制 | 低 | 中 |
| 68 | events-maths | 缺少事件-算术运算 | 低 | 中 |
| 69 | incorrect-unary | 危险的一元表达式 | 低 | 中 |
| 70 | missing-zero-check | 缺少零地址验证 | 低 | 中 |
| 71 | reentrancy-benign | 良性重入漏洞 | 低 | 中 |
| 72 | reentrancy-events | 导致事件乱序的重入漏洞 | 低 | 中 |
| 73 | return-bomb | 低级被调用者可能意外消耗所有调用者的 gas。 | 低 | 中 |
| 74 | timestamp | 危险的 block.timestamp 用法 | 低 | 中 |
| 75 | assembly | 汇编代码使用 | 信息 | 高 |
| 76 | assert-state-change | 断言状态变更 | 信息 | 高 |
| 77 | boolean-equal | 与布尔常量比较 | 信息 | 高 |
| 78 | cyclomatic-complexity | 检测圈复杂度高(>11)的函数 | 信息 | 高 |
| 79 | deprecated-standards | 已弃用的 Solidity 标准 | 信息 | 高 |
| 80 | erc20-indexed | 未索引的 ERC20 事件参数 | 信息 | 高 |
| 81 | function-init-state | 函数初始化状态变量 | 信息 | 高 |
| 82 | incorrect-using-for | 检测 using-for 语句中,给定库没有函数匹配给定类型 | 信息 | 高 |
| 83 | low-level-calls | 低级调用 | 信息 | 高 |
| 84 | missing-inheritance | 缺少继承 | 信息 | 高 |
| 85 | naming-convention | 符合 Solidity 命名约定 | 信息 | 高 |
| 86 | pragma | 使用了不同的 pragma 指令 | 信息 | 高 |
| 87 | redundant-statements | 冗余语句 | 信息 | 高 |
| 88 | solc-version | 不正确的 Solidity 版本 | 信息 | 高 |
| 89 | unimplemented-functions | 未实现的函数 | 信息 | 高 |
| 90 | unindexed-event-address | 包含地址参数但无索引参数的事件 | 信息 | 高 |
| 91 | unused-state | 未使用的状态变量 | 信息 | 高 |
| 92 | costly-loop | 循环中的昂贵操作 | 信息 | 中 |
| 93 | dead-code | 未使用的函数 | 信息 | 中 |
| 94 | reentrancy-unlimited-gas | 通过 send 和 transfer 的重入漏洞 | 信息 | 中 |
| 95 | too-many-digits | 符合数值记法最佳实践 | 信息 | 中 |
| 96 | cache-array-length | 检测在循环条件中使用某些存储数组的 length 成员且未修改它的 for 循环。 | 优化 | 高 |
| 97 | constable-states | 可声明为常量的状态变量 | 优化 | 高 |
| 98 | external-function | 可声明为 external 的 public 函数 | 优化 | 高 |
| 99 | immutable-states | 可声明为 immutable 的状态变量 | 优化 | 高 |
| 100 | var-read-using-this | 合约使用 this 读取自身的变量 | 优化 | 高 |
| 标题 | 用途 | 作者 | 会议/期刊 | 代码 |
|---|
| ReJection: A AST-Based Reentrancy Vulnerability Detection Method | 基于AST的分析,构建于Slither之上 | Rui Ma, Zefeng Jian, Guangyuan Chen, Ke Ma, Yujia Chen | CTCIS 19 | - |
| MPro: Combining Static and Symbolic Analysis for Scalable Testing of Smart Contract | 通过Slither利用数据依赖关系 | William Zhang, Sebastian Banescu, Leodardo Pasos, Steven Stewart, Vijay Ganesh | ISSRE 2019 | MPro |
| ETHPLOIT: From Fuzzing to Efficient Exploit Generation against Smart Contracts | 通过Slither利用数据依赖关系 | Qingzhao Zhang, Yizhuo Wang, Juanru Li, Siqi Ma | SANER 20 | - |
| Verification of Ethereum Smart Contracts: A Model Checking Approach | 基于Slither的CFG构建符号执行 | Tam Bang, Hoang H Nguyen, Dung Nguyen, Toan Trieu, Tho Quan | IJMLC 20 | - |
| Smart Contract Repair | 依赖Slither的漏洞检测器 | Xiao Liang Yu, Omar Al-Bataineh, David Lo, Abhik Roychoudhury | TOSEM 20 | SCRepair |
| Demystifying Loops in Smart Contracts | 通过Slither利用数据依赖关系 | Ben Mariano, Yanju Chen, Yu Feng, Shuvendu Lahiri, Isil Dillig | ASE 20 | - |
| Trace-Based Dynamic Gas Estimation of Loops in Smart Contracts | 使用Slither的CFG检测循环 | Chunmiao Li, Shijie Nie, Yang Cao, Yijun Yu, Zhenjiang Hu | IEEE Open J. Comput. Soc. 1 (2020) | - |
| SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in Seconds | 依赖SlithIR构建存储依赖图 | Priyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng, Christopher Kruegel, and Giovanni Vigna | S&P 22 | Sailfish |
| SolType: Refinement Types for Arithmetic Overflow in Solidity | 使用Slither作为前端构建细化类型系统 | Bryan Tan, Benjamin Mariano, Shuvendu K. Lahiri, Isil Dillig, Yu Feng | POPL 22 | - |
| Do Not Rug on Me: Leveraging Machine Learning Techniques for Automated Scam Detection | 使用Slither提取代币特征(可铸造、可暂停等) | Mazorra, Bruno, Victor Adan, and Vanesa Daza | Mathematics 10.6 (2022) | - |
| MANDO: Multi-Level Heterogeneous Graph Embeddings for Fine-Grained Detection of Smart Contract Vulnerabilities | 使用Slither提取CFG和调用图 | Hoang Nguyen, Nhat-Minh Nguyen, Chunyao Xie, Zahra Ahmadi, Daniel Kudendo, Thanh-Nam Doan and Lingxiao Jiang | IEEE 9th International Conference on Data Science and Advanced Analytics (DSAA, 2022) | ge-sc |
| Automated Auditing of Price Gouging TOD Vulnerabilities in Smart Contracts | 使用Slither提取CFG和数据依赖关系 | Sidi Mohamed Beillahi, Eric Keilty, Keerthi Nelaturu, Andreas Veneris, and Fan Long | 2022 IEEE International Conference on Blockchain and Cryptocurrency (ICBC) | Smart-Contract-Repair |
| Modeling and Enforcing Access Control Policies for Smart Contracts | 扩展Slither的数据依赖关系 | Jan-Philipp Toberg, Jonas Schiffl, Frederik Reiche, Bernhard Beckert, Robert Heinrich, Ralf Reussner | IEEE International Conference on Decentralized Applications and Infrastructures (DAPPS), 2022 | SolidityAccessControlEnforcement |
| Smart Contract Vulnerability Detection Based on Deep Learning and Multimodal Decision Fusion | 使用Slither提取CFG | Weichu Deng, Huanchun Wei, Teng Huang, Cong Cao, Yun Peng, and Xuan Hu | Sensors 2023, 23, 7246 | - |
| Semantic-enriched Code Knowledge Graph to Reveal Unknowns in Smart Contract Code Reuse | 使用Slither提取代码特征(CFG、函数、参数类型等) | Qing Huang, Dianshu Liao, Zhenchang Xing, Zhengkang Zuo, Changjing Wang, Xin Xia | ACM Transactions on Software Engineering and Methodology, 2023 | - |
| Smart Contract Parallel Execution with Fine-Grained State Accesses | 使用Slither构建状态访问图 | Xiaodong Qi, Jiao Jiao, Yi Li | International Conference on Distributed Computing Systems (ICDCS), 2023 | - |
| Bad Apples: Understanding the Centralized Security Risks in Decentralized Ecosystems | 在Slither之上实现内部分析 | Kailun Yan , Jilian Zhang , Xiangyu Liu , Wenrui Diao , Shanqing Guo | ACM Web Conference April 2023 | - |
| Identifying Vulnerabilities in Smart Contracts using Interval Analysis | 在Slither之上创建4个检测器 | Ştefan-Claudiu Susan, Andrei Arusoaie | FROM 2023 | - |
| Storage State Analysis and Extraction of Ethereum Blockchain Smart Contracts (no PDF in open access) | 依赖Slither的CFG和AST | Maha Ayub , Tania Saleem , Muhammad Janjua , Talha Ahmad | TOSEM 2023 | SmartMuv |