Skip to main content

get in touch with Consensys Diligence
[ 🌐 📩 ]

Legions

Ethereum Node Security Toolkit

Handy toolkit for (security) researchers poking around Ethereum nodes and contracts, now with a slick command-line interface, with auto complete commands and history.

Other functionalities:

  • Conversions (toWei, fromWei, keccak, etc)
  • Query for balance, code, storage of smart contracts, ecrecover
  • etc

This package is extremely beta

Installation

Require Python 3.7.0.

clone https://github.com/shayanb/Legions
cd Legions
pip install .

or

pip install legions

Usage

If installed locally:

python legions/main.py

or if installed globally:

legions

Functions

demo

Command [Subcommand] Description
sethost Setup the Web3 connection (RPC, IPC, HTTP) (default to infura mainnet)
getnodeinfo Information about the connected node (run setnode before this)
conversions Conversions possible to do with Web3
fromWei Converts the input to ether (to currency default to ether)
toWei Converts the input to Wei (from currency default to ether)
keccak keccak hash of the input
toBytes Converts the input to hex representation of its Bytes
toChecksumAddress Converts the input to Checksum Address
toHex Converts the input text to Hex
fromWei Converts the input to ether (or specified currency)
query Query Blockchain (Storage, balance, etc)
balance Get Balance of an account
block Get block details by block number
code Get code of the smart contract at address
ecrecover Get address associated with the signature (ecrecover) BUGGY
storage Read the storage of a contract (count default = 10)
command Manual RPC method with args
investigate Investigate further in the node (e.g. check if accounts are unlocked, etc)
accounts Investigate accounts (e.g. check if accounts are unlocked, etc)
admin Investigate accounts (e.g. functionalities under the admin_ namespace)
sign Investigate signature functionalities
version Print Versions (If connected to a node it will print the host version too)

Acknowledgement

TODO:

  • Fix Verbose Status bar (It does not change from OFF)
  • Print Accounts in getnodeinfo in a pretty format (One per line)
  • A way to reinitiate w3 (web3) by setting it to new host (right now it works for sethost but getnodeinfo still uses the first initiated w3)
  • add way more functionalities
  • chains.json depending on the execution path might not be found. fix it.
  • inline TODOs (tons)

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

legions-0.6.2.tar.gz (11.4 kB view details)

Uploaded Source

File details

Details for the file legions-0.6.2.tar.gz.

File metadata

  • Download URL: legions-0.6.2.tar.gz
  • Upload date:
  • Size: 11.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.1.0 requests-toolbelt/0.8.0 tqdm/4.41.1 CPython/3.8.1

File hashes

Hashes for legions-0.6.2.tar.gz
Algorithm Hash digest
SHA256 4d8caa2ccc3b81f3004e11c231aa606f799affa11971703abff4e2fbbbcd397c
MD5 017866e3d6537ed4891a8a13d74b50d2
BLAKE2b-256 b4535cbb2f9d272500a02f60757051bceba799bdf0efeb3b89d89c09c91ee1f0

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page