Skip to main content

An EVM symbolic execution tool and vulnerability scanner

Project description

Pakala

PyPI Build States

"ilo Pakala li pakala e mani sona"

  • Pakala is a tool to search for exploitable bugs in Ethereum smart contracts.
  • Pakala is a symbolic execution engine for the Ethereum Virtual Machine.

The intended public for the tool are security researchers interested by Ethereum / the EVM.

Installation

pip3 install pakala

It works only with python 3.

Usage

Let's look at 0xeBE6c7a839A660a0F04BdF6816e2eA182F5d542C: it has a transfer(address _to, uint256 _value) function. It is supposedly protected by a require(call.value - _value) >= 0 but that condition always holds because we are substracting two unsigned integers, so the result is also an unsigned integer.

Let's scan it:

./pakala.py 0xeBE6c7a839A660a0F04BdF6816e2eA182F5d542C --force-balance="1 ether"

The contract balance being 0, we won't be able to have it send us some ethers. So we override the balance to be 1 ETH: then it has some "virtual" money to send us.

The tool with tell you a bug was found, and dump you a path of "states". Each state corresponds to a transaction, with constraints that needs to be respected for that code path to be taken, storage that has been read/written...

Advice: look at calldata[0] in the constraints to see the function signature for each transaction.

See ./pakala.py help for more complete usage information.

How does it works? What does it do?

See the introductory article for more information and a demo.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pakala-1.0.12.tar.gz (31.3 kB view details)

Uploaded Source

Built Distribution

pakala-1.0.12-py3-none-any.whl (37.0 kB view details)

Uploaded Python 3

File details

Details for the file pakala-1.0.12.tar.gz.

File metadata

  • Download URL: pakala-1.0.12.tar.gz
  • Upload date:
  • Size: 31.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.28.1 CPython/3.7.2

File hashes

Hashes for pakala-1.0.12.tar.gz
Algorithm Hash digest
SHA256 e3b610d74af09951ff5ebbf7428a070ade96816b76b390599f9a7a67c6149693
MD5 643f0c98551935c6a837a1f786cd9e00
BLAKE2b-256 4de5f0a9c906e6b73ef1a7cbcbb180ef564b2ab1e7015dc6220574d6f86c8a3b

See more details on using hashes here.

File details

Details for the file pakala-1.0.12-py3-none-any.whl.

File metadata

  • Download URL: pakala-1.0.12-py3-none-any.whl
  • Upload date:
  • Size: 37.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.28.1 CPython/3.7.2

File hashes

Hashes for pakala-1.0.12-py3-none-any.whl
Algorithm Hash digest
SHA256 e916fa4979a6cfc287cdb3a0fce67b475e8c051007bdb17b2866c84f8ab7eda6
MD5 2742f29aff94ff0394ef3f845041f750
BLAKE2b-256 1a3d788de78a3b1ebef6bb0169268f0c09fad251a24bada85ac4be50aa083e68

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page