mirror of
https://github.com/cyber-defence-campus/morion
synced 2026-06-20 13:19:16 +00:00
945e1dd5d2ba39ac4c8242623a1a9336de803805
Morion
Installation
Triton
Dependencies
# libcapstone
curl -L https://github.com/capstone-engine/capstone/archive/refs/tags/4.0.2.tar.gz -o capstone.tar.gz
tar -xvzf capstone.tar.gz && rm capstone.tar.gz
mv capstone-4.0.2 Capstone && cd Capstone/
./make.sh
sudo ./make.sh install
# libboost, libpython and libz3
sudo apt install libboost-all-dev libpython3-dev libz3-dev
LibTriton
git clone https://github.com/JonathanSalwan/Triton && cd Triton/
mkdir build && cd build/
cmake ..
make -j4
sudo make install
Note: The Triton library is put into /usr/local/lib/python3.X/site-packages/, which is the default location for non-Debian Python packages built from source. Debian-based systems by default put Python packages built from source into /usr/local/lib/python3.X/dist-packages. To cope with this, you might create the following link on Debian-based systems (here for Python version 3.10):
sudo ln -s\
/usr/local/lib/python3.10/site-packages/triton.so \
/usr/local/lib/python3.10/dist-packages/triton.so
Morion
- Clone the repository:
git clone https://github.com/pdamian/morion.git && cd morion/
- Use a Python virtual enviroment (optional, but recommended):
- GDB uses the system-installed Python interpreter and the corresponding site-packages, even when using a Python virtual environment. In order to fix that, add the following to your
.gdbinitfile:
cat << EOF >> ~/.gdbinit
# Update GDB's Python paths with the ones from the local Python installation (e.g. to support virtual environments)
python
import os, subprocess, sys
paths = subprocess.check_output('python -c "import os, sys;print(os.linesep.join(sys.path).strip())"', shell=True).decode("utf-8").split()
sys.path.extend(paths)
end
EOF
- Create a virtual environment (with access to the system's site-packages to reach the Triton Python bindings)
python3 -mvenv venvs/morion --system-site-packages
source venvs/morion/bin/activate
- Install the package (add
-efor editable mode):
pip install .
Usage
Tracing
Tracing with GDB (or GDB-Multiarch):
gdb -q -x morion/tracing/gdb/trace.py
(gdb) morion_trace # Show usage
(gdb) help target # Attach to target binary
The .gdbinit file can be updated to automatically register Morion's tracing command at each launch of GDB:
cat << EOF >> ~/.gdbinit
# Register Morion's trace command `morion_trace` with GDB
source $PWD/Tools/Morion/morion/tracing/gdb/trace.py
EOF
Symbolic Execution
Symbolic execution of a binary's program trace:
morion -h # Perform symbolic execution
morion_backward_slicer -h # Use symbolic execution to calculate backward slices
morion_control_hijacker -h # Use symbolic execution to identify potential control flow hijacks
morion_memory_hijacker -h # Use symbolic execution to identify potential memory hijacks
morion_branch_analyzer -h # Use symbolic execution to analyze branches
morion_path_analyzer -h # Use symbolic execution to analyze paths
Description
Automated archival mirror of github.com/cyber-defence-campus/morion
685 KiB
Languages
Python
95.5%
C
2.8%
GDB
1.1%
Makefile
0.6%