Skip to main content

crackers: A Tool for Synthesizing Code-Reuse Attacks from p-code Programs

Build docs.rs

This package contains the Python bindings for crackers, a tool for synthesizing code-reuse attacks (e.g., ROP) built around the Z3 SMT Solver and Ghidra's SLEIGH code translator.

For more details, please refer to the GitHub project.

Usage

PyPI

The easiest way to use crackers is through the PyPI package. For every release, we provide wheels for [MacOS, Windows, Linux] x [3.11, 3.12, 3.13, 3.14].

A simple usage looks like the following:

import logging

from crackers.crackers import DecisionResult
from crackers.jingle import ModeledBlock, State

logging.basicConfig(level=logging.INFO)

from z3 import BoolRef, BoolVal, simplify

from crackers.config import (
    BinaryFileSpecification,
    ConstraintConfig,
    CrackersConfig,
    LibraryConfig,
    MetaConfig,
    ReferenceProgramConfig,
    SleighConfig,
    SynthesisConfig,
)
from crackers.config.constraint import (
    CustomStateConstraint,
    CustomTransitionConstraint,
    MemoryValuation,
    PointerRange,
    PointerRangeRole,
    RegisterStringValuation,
    RegisterValuation,
)
from crackers.config.log_level import LogLevel
from crackers.config.specification import BinaryFileSpecification, RawPcodeSpecification
from crackers.config.synthesis import SynthesisStrategy


# Custom state constraint example
def my_constraint(s: State, _addr: int) -> BoolRef:
    rdi = s.read_register("RDI")
    rcx = s.read_register("RCX")
    return rdi == (rcx ^ 0x5A5A5A5A5A5A5A5A)


# Custom transition constraint example
def my_transition_constraint(block: ModeledBlock) -> BoolRef:
    # Dummy: always true
    return BoolVal(True)


pcode = """
RBX = COPY 0x1337:8
BRANCH *[ram]0xdeadbeef:8
"""

meta = MetaConfig(log_level=LogLevel.DEBUG, seed=42)
library = LibraryConfig(
    max_gadget_length=8, path="libnscgi.so", sample_size=None, base_address=None
)
sleigh = SleighConfig(ghidra_path="/Applications/ghidra")
reference_program = RawPcodeSpecification(raw_pcode=pcode)
synthesis = SynthesisConfig(
    strategy=SynthesisStrategy.SAT,
    max_candidates_per_slot=200,
    parallel=8,
    combine_instructions=True,
)

constraint = ConstraintConfig(
    precondition=[
        RegisterValuation(name="RDI", value=0xDEADBEEF),
        MemoryValuation(space="ram", address=0x1000, size=4, value=0x41),
        RegisterStringValuation(reg="RSI", value="/bin/sh"),
        CustomStateConstraint.from_callable(my_constraint),
    ],
    postcondition=[
        RegisterValuation(name="RBX", value=0x1337),
    ],
    pointer=[
        PointerRange(role=PointerRangeRole.READ, min=0x80_0000, max=0x80_8000),
        CustomTransitionConstraint.from_callable(my_transition_constraint),
    ],
)
config = CrackersConfig(
    meta=meta,
    library=library,
    sleigh=sleigh,
    specification=reference_program,
    synthesis=synthesis,
    constraint=constraint,
)
r = config.run()
match r:
    case DecisionResult.AssignmentFound(a):
        for g in a.gadgets():
            for i in g.instructions:
                print(i.disassembly)
            print()
        for name, bv in a.input_summary(True):
            print(f"{name} = {hex(simplify(bv).as_long())}")

Research Paper

crackers was initially developed in support of our research paper, Synthesis of Code-Reuse Attacks from p-code Programs, presented at Usenix Security 2025.

If you found the paper or the implementation useful, you can cite it with the following BibTeX:

@inproceedings{10.5555/3766078.3766099,
author = {DenHoed, Mark and Melham, Tom},
title = {Synthesis of code-reuse attacks from p-code programs},
year = {2025},
isbn = {978-1-939133-52-6},
publisher = {USENIX Association},
address = {USA},
booktitle = {Proceedings of the 34th USENIX Conference on Security Symposium},
articleno = {21},
numpages = {17},
location = {Seattle, WA, USA},
series = {SEC '25}
}

Metadata

Release files for crackers 0.9.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for crackers 0.9.0
File Size Uploaded
crackers-0.9.0.tar.gz 83.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for crackers 0.9.0
File
crackers-0.9.0-cp314-cp314t-manylinux_2_28_x86_64.whl CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp314-cp314t-manylinux_2_28_aarch64.whl CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp314-cp314-win_amd64.whl CPython 3.14 CPython 3.14 Windows x86-64 Details
crackers-0.9.0-cp314-cp314-manylinux_2_28_x86_64.whl CPython 3.14 CPython 3.14 Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp314-cp314-manylinux_2_28_aarch64.whl CPython 3.14 CPython 3.14 Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp314-cp314-macosx_11_0_arm64.whl CPython 3.14 CPython 3.14 macOS 11.0+ ARM64 Details
crackers-0.9.0-cp313-cp313t-manylinux_2_28_x86_64.whl CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp313-cp313t-manylinux_2_28_aarch64.whl CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
crackers-0.9.0-cp313-cp313-manylinux_2_28_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp313-cp313-manylinux_2_28_aarch64.whl CPython 3.13 CPython 3.13 Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp313-cp313-macosx_11_0_arm64.whl CPython 3.13 CPython 3.13 macOS 11.0+ ARM64 Details
crackers-0.9.0-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
crackers-0.9.0-cp312-cp312-manylinux_2_28_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp312-cp312-manylinux_2_28_aarch64.whl CPython 3.12 CPython 3.12 Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp312-cp312-macosx_11_0_arm64.whl CPython 3.12 CPython 3.12 macOS 11.0+ ARM64 Details
crackers-0.9.0-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
crackers-0.9.0-cp311-cp311-manylinux_2_28_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.28+ x86-64 Details
crackers-0.9.0-cp311-cp311-manylinux_2_28_aarch64.whl CPython 3.11 CPython 3.11 Linux glibc 2.28+ ARM64 Details
crackers-0.9.0-cp311-cp311-macosx_11_0_arm64.whl CPython 3.11 CPython 3.11 macOS 11.0+ ARM64 Details

Total release size: 34.8 MB

Release files / crackers-0.9.0.tar.gz

Download URL crackers-0.9.0.tar.gz
Size 83.6 kB
Tags Source
SHA-256 checksum
How to use checksums
ee141d031507940ab63c7d8453eba860e9dd37f8e0f198101fca392c59810dad
BLAKE2b-256 checksum
How to use checksums
2fcfb82922c900094228582fdade7cd035dda49b1718d88e01d2efdd762c301a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314t-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp314-cp314t-manylinux_2_28_x86_64.whl
Size 1.8 MB
Tags CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
d2902d95dd3bccf7696e60cd9b968f83ebfa85b1b2cf0d74315f689141b7b719
BLAKE2b-256 checksum
How to use checksums
cda7155ef57583117af265332cefa03ce2e1f14cdb77e33f68fac6851933f6b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314t-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp314-cp314t-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.14 CPython 3.14 free-threading Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
561dba7f461f4b6f106a7f75b43733b829b606192f2efad3814df0c61b910408
BLAKE2b-256 checksum
How to use checksums
2a96fb8670762b626043af670beb88924e0ec753d20375330539d88c189f6e43
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314-win_amd64.whl

Download URL crackers-0.9.0-cp314-cp314-win_amd64.whl
Size 1.4 MB
Tags CPython 3.14 Windows x86-64
SHA-256 checksum
How to use checksums
715b2577982257698e51bf290d19b2ca4139f098728d642d2b60cf5991e34609
BLAKE2b-256 checksum
How to use checksums
59bf6763da3f3c17dd71a08c5d24ea8c620acc6a28531f7bddf4307cafb82ea9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp314-cp314-manylinux_2_28_x86_64.whl
Size 1.8 MB
Tags CPython 3.14 Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
9dd33688c4b405a33b3b9f4c7046a087871a88368975c2d11dfb038a401a25ff
BLAKE2b-256 checksum
How to use checksums
018146587c8bd79d2992315951631ba95f7e5def66a113f4280bf6da567e92a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp314-cp314-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.14 Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
96ccfccbd219198a574ab1858dc9396165e6f192e47f9adc503f9b834e5b94f8
BLAKE2b-256 checksum
How to use checksums
fdacf7ead8074c8228fa529e4a6613c07519a30aa8efed94f2bbb323e9c2f29c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp314-cp314-macosx_11_0_arm64.whl

Download URL crackers-0.9.0-cp314-cp314-macosx_11_0_arm64.whl
Size 1.6 MB
Tags CPython 3.14 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
c3d4fb76df6a57235af8c9f6d1a7889d9f046d205c6b0bccba55fea20448a51f
BLAKE2b-256 checksum
How to use checksums
134cde8cd73af16f420181aaf018f534ce12f67608ce61ff4bad4e39a505edf8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313t-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp313-cp313t-manylinux_2_28_x86_64.whl
Size 1.8 MB
Tags CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
df91f1454842ac935afbb0e90280150b888d91ba0230957fa159fa99b33a6ad8
BLAKE2b-256 checksum
How to use checksums
c26becd11b08a474f548f5088f47010e836f9f557ba14efd5895f9d1a06b347f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313t-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp313-cp313t-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.13 CPython 3.13 free-threading Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
52132f2fa8065b408d015aa028e8b7be41ecfcd72e49af9a04304dd4fb14419d
BLAKE2b-256 checksum
How to use checksums
52ddc81bf4473452a0b6bdfcec7cc1da5d1afcb4e954f5119f0467d0b2d659fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313-win_amd64.whl

Download URL crackers-0.9.0-cp313-cp313-win_amd64.whl
Size 1.5 MB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
22f4c06fd8ed007755ab39a6c0b09170a92a6e1268d07d38cf0f204a6bf3cfd9
BLAKE2b-256 checksum
How to use checksums
e1b988ebd5c2b5d5807b8213eee69ca96dbef026fdf68970901364b277f1f1cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp313-cp313-manylinux_2_28_x86_64.whl
Size 1.8 MB
Tags CPython 3.13 Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
893957152b345bcd220694e0e561e52d1b4fc8dd6ceab82dded06fb185ac432e
BLAKE2b-256 checksum
How to use checksums
f0d90d94a0e5ae9dfcd617a91fb97184fe528c346b6325c08569e3f7de289f23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp313-cp313-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.13 Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
af8944f9b715a5fd044d066bc4d068e31a6907299bd9724776d3c0abd1264634
BLAKE2b-256 checksum
How to use checksums
313cd56f72aed8e4e88f649980b53a3a4cc471ea965c2ea3262339f8ef67b754
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp313-cp313-macosx_11_0_arm64.whl

Download URL crackers-0.9.0-cp313-cp313-macosx_11_0_arm64.whl
Size 1.7 MB
Tags CPython 3.13 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
baac9568475821f29f0649b3d72704b916b64e78302eafc01838452fcbe964d0
BLAKE2b-256 checksum
How to use checksums
a1811e351bfc8a17cffaeb3918004a15746e35c8c9f5284162dd74a953599b50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp312-cp312-win_amd64.whl

Download URL crackers-0.9.0-cp312-cp312-win_amd64.whl
Size 1.5 MB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
1853d57c737f20442e1aa49f5e4cbfafc0ce51014186940ae2a397adf8aa5ec5
BLAKE2b-256 checksum
How to use checksums
661aa0770151646e550df11ecd42aed111e0c12ecc884986608cf88517096058
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp312-cp312-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp312-cp312-manylinux_2_28_x86_64.whl
Size 1.8 MB
Tags CPython 3.12 Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
9f41989db0a1107abd4fdc21c6fa2219ce2647bff829e596bfdbb62aebc82943
BLAKE2b-256 checksum
How to use checksums
eed312ed9e669112f5aad93172dab3b304bf89015ce081b298328543d888966d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp312-cp312-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp312-cp312-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.12 Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
a524dc7b10b520bb5e80a68037732606dcfb64d58d631bb60679ba736910f2a7
BLAKE2b-256 checksum
How to use checksums
78bbbaee9e1b1beb51f359e458ab0ce033471dae20306e629bbe2e56b0f21cb3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp312-cp312-macosx_11_0_arm64.whl

Download URL crackers-0.9.0-cp312-cp312-macosx_11_0_arm64.whl
Size 1.7 MB
Tags CPython 3.12 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
168c51820b0b901ac2cf8299597e4bc1247932993dad3cac4bfdf87746416613
BLAKE2b-256 checksum
How to use checksums
edad58a6593987b1d326b38602f5d7b82fe0dd312712d63387445dd46b343508
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp311-cp311-win_amd64.whl

Download URL crackers-0.9.0-cp311-cp311-win_amd64.whl
Size 1.5 MB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
3c07406a2984e5782ba6be56862cee5c6a99fffd62b33060a816f364a8002296
BLAKE2b-256 checksum
How to use checksums
f56bb4f20e346fe5a850fdba9938cc2afa4dcb3e2bb6f24fa69f02ba29663ad4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp311-cp311-manylinux_2_28_x86_64.whl

Download URL crackers-0.9.0-cp311-cp311-manylinux_2_28_x86_64.whl
Size 1.9 MB
Tags CPython 3.11 Linux glibc 2.28+ x86-64
SHA-256 checksum
How to use checksums
ce6395437f5cb9e899d9c777f59586b91fd40e2b501e3591e38d92231a88b9ed
BLAKE2b-256 checksum
How to use checksums
eec19101d014090a0ef72b5974938a1626445993e51d8400e4e9468f48399081
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp311-cp311-manylinux_2_28_aarch64.whl

Download URL crackers-0.9.0-cp311-cp311-manylinux_2_28_aarch64.whl
Size 1.9 MB
Tags CPython 3.11 Linux glibc 2.28+ ARM64
SHA-256 checksum
How to use checksums
41d762f77f75a4b5974a1ae8e667b9a19e297e870ce1c3c932d49526e97bcf44
BLAKE2b-256 checksum
How to use checksums
dff3af5d935270f0623378af4cef3ea25447f0ad7a31e3ea0731d660fe8e6c5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release files / crackers-0.9.0-cp311-cp311-macosx_11_0_arm64.whl

Download URL crackers-0.9.0-cp311-cp311-macosx_11_0_arm64.whl
Size 1.7 MB
Tags CPython 3.11 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
7dddbdea8d8fb980c795d6bbf42bf262a34e24f48eb3820affb878b5cd75d4b5
BLAKE2b-256 checksum
How to use checksums
df735a1efbec6c283598d282247c7366bcd668db4cb4fbdcdce45dfa79cbf3ea
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via maturin/1.10.2

Release history Release notifications | RSS feed

This release

0.9.0 This release

21 release files

0.8.1

21 release files

0.8.0

21 release files

0.7.0

21 release files

0.6.2

21 release files

0.6.1

20 release files

0.6.0

21 release files

0.5.4

25 release files

0.5.3

22 release files

0.5.1

23 release files

0.5.0

23 release files

0.4.0

23 release files

0.2.1

22 release files

0.2.0

22 release files

0.1.3

22 release files

0.1.2

22 release files

0.1.0

22 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page