2023-01-19 13:46:48 +01:00
2023-01-18 15:16:25 +01:00
2023-01-18 15:16:25 +01:00
2023-01-09 10:30:43 +01:00
2022-04-19 14:37:03 +02:00
2023-01-19 13:46:48 +01:00
2022-04-26 14:18:27 +02:00

Morion

Installation

Triton

Dependencies

# libcapstone
curl -L https://github.com/capstone-engine/capstone/archive/refs/tags/4.0.2.tar.gz -o capstone.tar.gz
tar -xvzf capstone.tar.gz && rm capstone.tar.gz
mv capstone-4.0.2 Capstone && cd Capstone/
./make.sh
sudo ./make.sh install

# libboost, libpython and libz3
sudo apt install libboost-all-dev libpython3-dev libz3-dev

LibTriton

git clone https://github.com/JonathanSalwan/Triton && cd Triton/
mkdir build && cd build/
cmake ..
make -j4
sudo make install

Note: The Triton library is put into /usr/local/lib/python3.X/site-packages/, which is the default location for non-Debian Python packages built from source. Debian-based systems by default put Python packages built from source into /usr/local/lib/python3.X/dist-packages. To cope with this, you might create the following link on Debian-based systems (here for Python version 3.10):

sudo ln -s\
  /usr/local/lib/python3.10/site-packages/triton.so \
  /usr/local/lib/python3.10/dist-packages/triton.so

Morion

  1. Clone the repository:
git clone https://github.com/pdamian/morion.git && cd morion/
  1. Use a Python virtual enviroment (optional, but recommended):
  • GDB uses the system-installed Python interpreter and the corresponding site-packages, even when using a Python virtual environment. In order to fix that, add the following to your .gdbinit file:
cat << EOF >> ~/.gdbinit

# Update GDB's Python paths with the ones from the local Python installation (e.g. to support virtual environments)
python
import os, subprocess, sys
paths = subprocess.check_output('python -c "import os, sys;print(os.linesep.join(sys.path).strip())"', shell=True).decode("utf-8").split()
sys.path.extend(paths)
end
EOF
  • Create a virtual environment (with access to the system's site-packages to reach the Triton Python bindings)
python3 -mvenv venvs/morion --system-site-packages
source venvs/morion/bin/activate
  1. Install the package (add -e for editable mode):
pip install .

Usage

Tracing

Tracing with GDB (or GDB-Multiarch):

gdb -q -x morion/tracing/gdb/trace.py
(gdb) morion_trace                    # Show usage
(gdb) help target                     # Attach to target binary

The .gdbinit file can be updated to automatically register Morion's tracing command at each launch of GDB:

cat << EOF >> ~/.gdbinit

# Register Morion's trace command `morion_trace` with GDB 
source $PWD/Tools/Morion/morion/tracing/gdb/trace.py
EOF

Symbolic Execution

Symbolic execution of a binary's program trace:

morion -h                   # Perform symbolic execution
morion_backward_slicer  -h  # Use symbolic execution to calculate backward slices
morion_control_hijacker -h  # Use symbolic execution to identify potential control flow hijacks
morion_memory_hijacker  -h  # Use symbolic execution to identify potential memory hijacks
morion_branch_analyzer  -h  # Use symbolic execution to analyze branches
morion_path_analyzer    -h  # Use symbolic execution to analyze paths
S
Description
Automated archival mirror of github.com/cyber-defence-campus/morion
Readme Apache-2.0
685 KiB
Languages
Python 95.5%
C 2.8%
GDB 1.1%
Makefile 0.6%