Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
seccomp-tools — 为seccomp分析提供强大的工具 | Kitploit
工具/GitHubGitHub/david942j/seccomp-tools
动态分析 (沙盒)逆向工程CTF二进制分析学习与教育
GitHubdavid942j/seccomp-tools

seccomp-tools

为seccomp分析提供强大的工具

查看仓库
1.1k73376天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Downloads

Gem Version Build Status Maintainability Code Coverage Inline docs Yard Docs MIT License

Seccomp Tools

用于 seccomp 分析的强大工具。

本项目主要(但并非仅)面向 CTF pwn 挑战中 seccomp 沙箱的分析。 部分功能为 CTF 专属,但同样适用于分析真实世界中的 seccomp 过滤器。

功能特性

  • Dump - 自动从可执行文件中转储 seccomp BPF。
  • Disasm - 将 seccomp BPF 转换为人类可读的格式。
    • 支持简单的反编译。
    • 尽可能显示系统调用名称及参数。
    • 彩色输出!
  • Asm - 让编写 seccomp 规则像编写代码一样简单。
  • Emu - 模拟执行 seccomp 规则。
  • Explain - 将过滤器总结为按动作划分的策略(哪些系统调用被允许/禁止,以及何时生效)。
  • Audit - 扫描过滤器中的弱点与逃逸路径(缺失的 arch/x32 防护、危险系统调用等)。
  • 多架构支持。

安装

可在 RubyGems.org 上获取!``` $ gem install seccomp-tools

如果编译失败,请尝试:```
sudo apt install gcc ruby-dev make

然后重新安装 seccomp-tools。

命令行界面

seccomp-tools```bash

$ seccomp-tools --help

Usage: seccomp-tools [--version] [--help] []

List of commands:

asm Seccomp bpf assembler.

audit Assess a seccomp filter for weaknesses and escape routes.

completion Print a shell completion script.

disasm Disassemble seccomp bpf.

dump Automatically dump seccomp bpf from executable(s).

emu Emulate seccomp rules.

explain Summarize a seccomp filter as a per-action policy.

See 'seccomp-tools --help' to read about a specific subcommand.

$ seccomp-tools dump --help

dump - Automatically dump seccomp bpf from executable(s).

NOTE: This command is only available on Linux.

Usage: seccomp-tools dump [EXEC] [options]

-c, --sh-exec Executes the given command (via sh) and dumps its seccomp.

Use this to pass arguments or pipe things to the executable.

e.g. use -c "./bin > /dev/null" to keep the program output out of the result.

Takes precedence over the positional argument.

-l, --limit LIMIT Dump only the first LIMIT installed filters.

Only meaningful when the input is an executable or --pid. Default: 1

An executable is killed once it reaches LIMIT.

-p, --pid PID Dump the seccomp filters installed on an existing process.

You must have CAP_SYS_ADMIN (e.g. be root) to use this option.

-t, --timeout SEC Timeout (seconds) for the execution. Default: no timeout

This option is ignored when --pid is given.

-f, --format FORMAT Output format. FORMAT can only be one of <disasm|raw|inspect>.

Default: disasm

-o, --output FILE Write output to FILE instead of stdout.

If multiple seccomp syscalls have been invoked (see --limit),

results are written to FILE, FILE_1, FILE_2, etc.

For example, with "--output out.bpf" the output files are out.bpf, out_1.bpf, ...

### dump

使用 `ptrace` 系统调用从可执行文件中转储 seccomp BPF。

注意:目标可执行文件实际上会被运行,因此请谨慎对待不受信任的二进制文件。```bash
$ file spec/binary/twctf-2016-diary
# spec/binary/twctf-2016-diary: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.24, BuildID[sha1]=3648e29153ac0259a0b7c3e25537a5334f50107f, not stripped

$ seccomp-tools dump spec/binary/twctf-2016-diary
#  line  CODE  JT   JF      K
# =================================
#  0000: 0x20 0x00 0x00 0x00000000  A = sys_number
#  0001: 0x15 0x00 0x01 0x00000002  if (A != open) goto 0003
#  0002: 0x06 0x00 0x00 0x00000000  return KILL
#  0003: 0x15 0x00 0x01 0x00000101  if (A != openat) goto 0005
#  0004: 0x06 0x00 0x00 0x00000000  return KILL
#  0005: 0x15 0x00 0x01 0x0000003b  if (A != execve) goto 0007
#  0006: 0x06 0x00 0x00 0x00000000  return KILL
#  0007: 0x15 0x00 0x01 0x00000038  if (A != clone) goto 0009
#  0008: 0x06 0x00 0x00 0x00000000  return KILL
#  0009: 0x15 0x00 0x01 0x00000039  if (A != fork) goto 0011
#  0010: 0x06 0x00 0x00 0x00000000  return KILL
#  0011: 0x15 0x00 0x01 0x0000003a  if (A != vfork) goto 0013
#  0012: 0x06 0x00 0x00 0x00000000  return KILL
#  0013: 0x15 0x00 0x01 0x00000055  if (A != creat) goto 0015
#  0014: 0x06 0x00 0x00 0x00000000  return KILL
#  0015: 0x15 0x00 0x01 0x00000142  if (A != execveat) goto 0017
#  0016: 0x06 0x00 0x00 0x00000000  return KILL
#  0017: 0x06 0x00 0x00 0x7fff0000  return ALLOW

$ seccomp-tools dump spec/binary/twctf-2016-diary -f inspect
# "\x20\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x02\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x01\x01\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x3B\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x38\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x39\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x3A\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x55\x00\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x15\x00\x00\x01\x42\x01\x00\x00\x06\x00\x00\x00\x00\x00\x00\x00\x06\x00\x00\x00\x00\x00\xFF\x7F"

$ seccomp-tools dump spec/binary/twctf-2016-diary -f raw | xxd
# 00000000: 2000 0000 0000 0000 1500 0001 0200 0000   ...............
# 00000010: 0600 0000 0000 0000 1500 0001 0101 0000  ................
# 00000020: 0600 0000 0000 0000 1500 0001 3b00 0000  ............;...
# 00000030: 0600 0000 0000 0000 1500 0001 3800 0000  ............8...
# 00000040: 0600 0000 0000 0000 1500 0001 3900 0000  ............9...
# 00000050: 0600 0000 0000 0000 1500 0001 3a00 0000  ............:...
# 00000060: 0600 0000 0000 0000 1500 0001 5500 0000  ............U...
# 00000070: 0600 0000 0000 0000 1500 0001 4201 0000  ............B...
# 00000080: 0600 0000 0000 0000 0600 0000 0000 ff7f  ................

disasm

将原始 seccomp BPF 反汇编为可读格式。```bash $ xxd spec/data/twctf-2016-diary.bpf | head -n 3

00000000: 2000 0000 0000 0000 1500 0001 0200 0000 ...............

00000010: 0600 0000 0000 0000 1500 0001 0101 0000 ................

00000020: 0600 0000 0000 0000 1500 0001 3b00 0000 ............;...

下载工具