vagd.virts.cogd
Classes
Functions
|
Module Contents
- vagd.virts.cogd._stop_for_debugger(aslr, rlimits)
- class vagd.virts.cogd.Cogd(binary: str, containerhome: str, cogd_type: str, lockfile: str, image: str = DEFAULT_IMAGE, user: str = DEFAULT_USER, forward: Dict[str, int] | None = None, packages: List[str] | None = None, cap_add: List[str] | None = None, privileged: bool = False, symbols: bool = True, rm: bool = True, ex: bool = False, fast: bool = False, alpine: bool = False, native: bool = True, **kwargs: Any)
Bases:
vagd.virts.shgd.ShgdContainer virtualization for pwntools- Parameters:
binary – binary to execute
containerhome – home directory of container runtime
lockfile – lockfile of container runtime
cogd_type – type of container tool
image – docker base image
user – name of user on docker container
forward – Dictionary of forwarded ports, needs to follow docker api format: ‘hostport/(tcp|udp)’ : guestport
packages – packages to install on the container
cap_add – Linux capabilities to add to the container
privileged – run the container with extended privileges
symbols – additionally install libc6 debug symbols (also updates libc6)
ex – if experimental features, e.g. alpine, gdbserver should be enabled
rm – remove container after exit
alpine – if the conainter is alpine (also autochecks image name)
fast – mounts libs locally for faster symbol extraction (experimental) NOT COMPATIBLE WITH ALPINE
native – attach the host gdb directly to the process instead of using gdbserver (requires same uid)
kwargs – parameters to pass through to super
- _image: str
- _name: str
- _user: str
- _port: int
- _packages: List[str]
- _client: docker.DockerClient | podman.PodmanClient
- _id: str
- _containerdir: str
- _dockerfile: str
- _has_not_apt: bool
- _rm: bool
- _ex: bool
- _forward: Dict[str, int]
- _symbols: bool
- _i386: bool
- _template: str
- _containerhome: str
- _lockfile: str
- _type: str
- _native: bool
- _native_ok: bool | None = None
- VAGD_PREFIX = 'vagd-'
- DEFAULT_USER = 'vagd'
- DEFAULT_PORT = 2222
- DEFAULT_IMAGE = 'ubuntu:noble'
- DEFAULT_PACKAGES = ['gdbserver', 'python3', 'sudo', 'socat', 'openssh-server']
- _cap_add = []
- _privileged = False
- _create_dockerfile()
- _create_container_instance()
- _build_image()
- _vm_setup() None
pass
- _vm_create()
- abstractmethod _client_setup() Any
- _init_pid() int
host pid of the container’s init process
- static _status(pid: int) Dict[str, str]
parse /proc/<pid>/status
- _host_pid(pid: int) int | None
translate a pid inside the container to a host pid
- Parameters:
pid – pid inside the container
- Returns:
host pid or None if not found
- _child_pid(parent: int, tries: int = 200) int | None
host pid of the first child of a host process, polls while the child is spawned
- _native_supported() bool
check if the host gdb is allowed to ptrace processes inside the container
- process(argv: list[str] | None = None, socket: bool | None = None, native: bool | None = None, ulimit: Dict[str, Any] | None = None, **kwargs: Any) pwnlib.tubes.tube.tube
run binary in container as process
- Parameters:
argv – comandline arguments for binary
socket – override the instance’s socket transport setting
native – ignored, only relevant for debug
ulimit – override the instance’s resource limits
kwargs – pwntool parameters
- Returns:
pwntools process
- debug(argv: list[str] | None = None, gdb_args: list[str] | None = None, gdbscript: str = '', sysroot: str | None = None, sysroot_debug: str | None = None, socket: bool | None = None, native: bool | None = None, api: bool = False, ulimit: Dict[str, Any] | None = None, **kwargs: Any) pwnlib.tubes.tube.tube
run binary in container with gdb, attaches the host gdb directly if possible
- Parameters:
argv – comandline arguments for binary
gdb_args – gdb args to forward to gdb
gdbscript – GDB script for GDB
sysroot – sysroot dir (ignored for native attach)
sysroot_debug – sysroot debug lib dir (ignored for native attach)
socket – override the instance’s socket transport setting
native – override the instance’s native attach setting
api – if GDB API should be enabled
ulimit – override the instance’s resource limits
kwargs – pwntool parameters
- Returns:
pwntools process