crackers: A Tool for Synthesizing Code-Reuse Attacks from p-code Programs
This package contains the Python bindings for crackers, a tool for synthesizing
code-reuse attacks (e.g., ROP) built around the Z3 SMT Solver and Ghidra's SLEIGH code translator.
For more details, please refer to the GitHub project.
Usage
The easiest way to use crackers is through the PyPI package. For every release, we provide wheels for [MacOS, Windows, Linux] x [3.11, 3.12, 3.13, 3.14].
A simple usage looks like the following:
import logging
from crackers.crackers import DecisionResult
from crackers.jingle import ModeledBlock, State
logging.basicConfig(level=logging.INFO)
from z3 import BoolRef, BoolVal, simplify
from crackers.config import (
BinaryFileSpecification,
ConstraintConfig,
CrackersConfig,
LibraryConfig,
MetaConfig,
ReferenceProgramConfig,
SleighConfig,
SynthesisConfig,
)
from crackers.config.constraint import (
CustomStateConstraint,
CustomTransitionConstraint,
MemoryValuation,
PointerRange,
PointerRangeRole,
RegisterStringValuation,
RegisterValuation,
)
from crackers.config.log_level import LogLevel
from crackers.config.specification import BinaryFileSpecification, RawPcodeSpecification
from crackers.config.synthesis import SynthesisStrategy
# Custom state constraint example
def my_constraint(s: State, _addr: int) -> BoolRef:
rdi = s.read_register("RDI")
rcx = s.read_register("RCX")
return rdi == (rcx ^ 0x5A5A5A5A5A5A5A5A)
# Custom transition constraint example
def my_transition_constraint(block: ModeledBlock) -> BoolRef:
# Dummy: always true
return BoolVal(True)
pcode = """
RBX = COPY 0x1337:8
BRANCH *[ram]0xdeadbeef:8
"""
meta = MetaConfig(log_level=LogLevel.DEBUG, seed=42)
library = LibraryConfig(
max_gadget_length=8, path="libnscgi.so", sample_size=None, base_address=None
)
sleigh = SleighConfig(ghidra_path="/Applications/ghidra")
reference_program = RawPcodeSpecification(raw_pcode=pcode)
synthesis = SynthesisConfig(
strategy=SynthesisStrategy.SAT,
max_candidates_per_slot=200,
parallel=8,
combine_instructions=True,
)
constraint = ConstraintConfig(
precondition=[
RegisterValuation(name="RDI", value=0xDEADBEEF),
MemoryValuation(space="ram", address=0x1000, size=4, value=0x41),
RegisterStringValuation(reg="RSI", value="/bin/sh"),
CustomStateConstraint.from_callable(my_constraint),
],
postcondition=[
RegisterValuation(name="RBX", value=0x1337),
],
pointer=[
PointerRange(role=PointerRangeRole.READ, min=0x80_0000, max=0x80_8000),
CustomTransitionConstraint.from_callable(my_transition_constraint),
],
)
config = CrackersConfig(
meta=meta,
library=library,
sleigh=sleigh,
specification=reference_program,
synthesis=synthesis,
constraint=constraint,
)
r = config.run()
match r:
case DecisionResult.AssignmentFound(a):
for g in a.gadgets():
for i in g.instructions:
print(i.disassembly)
print()
for name, bv in a.input_summary(True):
print(f"{name} = {hex(simplify(bv).as_long())}")
Research Paper
crackers was initially developed in support of our research paper, Synthesis of Code-Reuse Attacks from p-code Programs,
presented at Usenix Security 2025.
If you found the paper or the implementation useful, you can cite it with the following BibTeX:
@inproceedings{10.5555/3766078.3766099,
author = {DenHoed, Mark and Melham, Tom},
title = {Synthesis of code-reuse attacks from p-code programs},
year = {2025},
isbn = {978-1-939133-52-6},
publisher = {USENIX Association},
address = {USA},
booktitle = {Proceedings of the 34th USENIX Conference on Security Symposium},
articleno = {21},
numpages = {17},
location = {Seattle, WA, USA},
series = {SEC '25}
}
Metadata
Release files for crackers 0.9.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| crackers-0.9.0.tar.gz | 83.6 kB | Details |
Built distributions (wheels)
Total release size: 34.8 MB
Release files / crackers-0.9.0.tar.gz
| Download URL | crackers-0.9.0.tar.gz |
|---|---|
| Size | 83.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ee141d031507940ab63c7d8453eba860e9dd37f8e0f198101fca392c59810dad
|
|
BLAKE2b-256 checksum How to use checksums |
2fcfb82922c900094228582fdade7cd035dda49b1718d88e01d2efdd762c301a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314t-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp314-cp314t-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.8 MB |
| Tags | CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
d2902d95dd3bccf7696e60cd9b968f83ebfa85b1b2cf0d74315f689141b7b719
|
|
BLAKE2b-256 checksum How to use checksums |
cda7155ef57583117af265332cefa03ce2e1f14cdb77e33f68fac6851933f6b2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314t-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp314-cp314t-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
561dba7f461f4b6f106a7f75b43733b829b606192f2efad3814df0c61b910408
|
|
BLAKE2b-256 checksum How to use checksums |
2a96fb8670762b626043af670beb88924e0ec753d20375330539d88c189f6e43
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314-win_amd64.whl
| Download URL | crackers-0.9.0-cp314-cp314-win_amd64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.14 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
715b2577982257698e51bf290d19b2ca4139f098728d642d2b60cf5991e34609
|
|
BLAKE2b-256 checksum How to use checksums |
59bf6763da3f3c17dd71a08c5d24ea8c620acc6a28531f7bddf4307cafb82ea9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp314-cp314-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.8 MB |
| Tags | CPython 3.14 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
9dd33688c4b405a33b3b9f4c7046a087871a88368975c2d11dfb038a401a25ff
|
|
BLAKE2b-256 checksum How to use checksums |
018146587c8bd79d2992315951631ba95f7e5def66a113f4280bf6da567e92a6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp314-cp314-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.14 Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
96ccfccbd219198a574ab1858dc9396165e6f192e47f9adc503f9b834e5b94f8
|
|
BLAKE2b-256 checksum How to use checksums |
fdacf7ead8074c8228fa529e4a6613c07519a30aa8efed94f2bbb323e9c2f29c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp314-cp314-macosx_11_0_arm64.whl
| Download URL | crackers-0.9.0-cp314-cp314-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.6 MB |
| Tags | CPython 3.14 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
c3d4fb76df6a57235af8c9f6d1a7889d9f046d205c6b0bccba55fea20448a51f
|
|
BLAKE2b-256 checksum How to use checksums |
134cde8cd73af16f420181aaf018f534ce12f67608ce61ff4bad4e39a505edf8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313t-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp313-cp313t-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.8 MB |
| Tags | CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
df91f1454842ac935afbb0e90280150b888d91ba0230957fa159fa99b33a6ad8
|
|
BLAKE2b-256 checksum How to use checksums |
c26becd11b08a474f548f5088f47010e836f9f557ba14efd5895f9d1a06b347f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313t-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp313-cp313t-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
52132f2fa8065b408d015aa028e8b7be41ecfcd72e49af9a04304dd4fb14419d
|
|
BLAKE2b-256 checksum How to use checksums |
52ddc81bf4473452a0b6bdfcec7cc1da5d1afcb4e954f5119f0467d0b2d659fa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313-win_amd64.whl
| Download URL | crackers-0.9.0-cp313-cp313-win_amd64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | CPython 3.13 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
22f4c06fd8ed007755ab39a6c0b09170a92a6e1268d07d38cf0f204a6bf3cfd9
|
|
BLAKE2b-256 checksum How to use checksums |
e1b988ebd5c2b5d5807b8213eee69ca96dbef026fdf68970901364b277f1f1cd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp313-cp313-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.8 MB |
| Tags | CPython 3.13 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
893957152b345bcd220694e0e561e52d1b4fc8dd6ceab82dded06fb185ac432e
|
|
BLAKE2b-256 checksum How to use checksums |
f0d90d94a0e5ae9dfcd617a91fb97184fe528c346b6325c08569e3f7de289f23
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp313-cp313-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.13 Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
af8944f9b715a5fd044d066bc4d068e31a6907299bd9724776d3c0abd1264634
|
|
BLAKE2b-256 checksum How to use checksums |
313cd56f72aed8e4e88f649980b53a3a4cc471ea965c2ea3262339f8ef67b754
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp313-cp313-macosx_11_0_arm64.whl
| Download URL | crackers-0.9.0-cp313-cp313-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.13 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
baac9568475821f29f0649b3d72704b916b64e78302eafc01838452fcbe964d0
|
|
BLAKE2b-256 checksum How to use checksums |
a1811e351bfc8a17cffaeb3918004a15746e35c8c9f5284162dd74a953599b50
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp312-cp312-win_amd64.whl
| Download URL | crackers-0.9.0-cp312-cp312-win_amd64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | CPython 3.12 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
1853d57c737f20442e1aa49f5e4cbfafc0ce51014186940ae2a397adf8aa5ec5
|
|
BLAKE2b-256 checksum How to use checksums |
661aa0770151646e550df11ecd42aed111e0c12ecc884986608cf88517096058
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp312-cp312-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp312-cp312-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.8 MB |
| Tags | CPython 3.12 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
9f41989db0a1107abd4fdc21c6fa2219ce2647bff829e596bfdbb62aebc82943
|
|
BLAKE2b-256 checksum How to use checksums |
eed312ed9e669112f5aad93172dab3b304bf89015ce081b298328543d888966d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp312-cp312-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp312-cp312-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.12 Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
a524dc7b10b520bb5e80a68037732606dcfb64d58d631bb60679ba736910f2a7
|
|
BLAKE2b-256 checksum How to use checksums |
78bbbaee9e1b1beb51f359e458ab0ce033471dae20306e629bbe2e56b0f21cb3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp312-cp312-macosx_11_0_arm64.whl
| Download URL | crackers-0.9.0-cp312-cp312-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.12 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
168c51820b0b901ac2cf8299597e4bc1247932993dad3cac4bfdf87746416613
|
|
BLAKE2b-256 checksum How to use checksums |
edad58a6593987b1d326b38602f5d7b82fe0dd312712d63387445dd46b343508
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp311-cp311-win_amd64.whl
| Download URL | crackers-0.9.0-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 1.5 MB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
3c07406a2984e5782ba6be56862cee5c6a99fffd62b33060a816f364a8002296
|
|
BLAKE2b-256 checksum How to use checksums |
f56bb4f20e346fe5a850fdba9938cc2afa4dcb3e2bb6f24fa69f02ba29663ad4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp311-cp311-manylinux_2_28_x86_64.whl
| Download URL | crackers-0.9.0-cp311-cp311-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.11 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
ce6395437f5cb9e899d9c777f59586b91fd40e2b501e3591e38d92231a88b9ed
|
|
BLAKE2b-256 checksum How to use checksums |
eec19101d014090a0ef72b5974938a1626445993e51d8400e4e9468f48399081
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp311-cp311-manylinux_2_28_aarch64.whl
| Download URL | crackers-0.9.0-cp311-cp311-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 1.9 MB |
| Tags | CPython 3.11 Linux glibc 2.28+ ARM64 |
|
SHA-256 checksum How to use checksums |
41d762f77f75a4b5974a1ae8e667b9a19e297e870ce1c3c932d49526e97bcf44
|
|
BLAKE2b-256 checksum How to use checksums |
dff3af5d935270f0623378af4cef3ea25447f0ad7a31e3ea0731d660fe8e6c5f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|
Release files / crackers-0.9.0-cp311-cp311-macosx_11_0_arm64.whl
| Download URL | crackers-0.9.0-cp311-cp311-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.11 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
7dddbdea8d8fb980c795d6bbf42bf262a34e24f48eb3820affb878b5cd75d4b5
|
|
BLAKE2b-256 checksum How to use checksums |
df735a1efbec6c283598d282247c7366bcd668db4cb4fbdcdce45dfa79cbf3ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
maturin/1.10.2
|