vagd.virts.cogd

Classes

Cogd

Functions

_stop_for_debugger(aslr, rlimits)

Module Contents

vagd.virts.cogd._stop_for_debugger(aslr, rlimits)
class vagd.virts.cogd.Cogd(binary: str, containerhome: str, cogd_type: str, lockfile: str, image: str = DEFAULT_IMAGE, user: str = DEFAULT_USER, forward: Dict[str, int] | None = None, packages: List[str] | None = None, cap_add: List[str] | None = None, privileged: bool = False, symbols: bool = True, rm: bool = True, ex: bool = False, fast: bool = False, alpine: bool = False, native: bool = True, **kwargs: Any)

Bases: vagd.virts.shgd.Shgd

Container virtualization for pwntools
Parameters:
  • binary – binary to execute

  • containerhome – home directory of container runtime

  • lockfile – lockfile of container runtime

  • cogd_type – type of container tool

  • image – docker base image

  • user – name of user on docker container

  • forward – Dictionary of forwarded ports, needs to follow docker api format: ‘hostport/(tcp|udp)’ : guestport

  • packages – packages to install on the container

  • cap_add – Linux capabilities to add to the container

  • privileged – run the container with extended privileges

  • symbols – additionally install libc6 debug symbols (also updates libc6)

  • ex – if experimental features, e.g. alpine, gdbserver should be enabled

  • rm – remove container after exit

  • alpine – if the conainter is alpine (also autochecks image name)

  • fast – mounts libs locally for faster symbol extraction (experimental) NOT COMPATIBLE WITH ALPINE

  • native – attach the host gdb directly to the process instead of using gdbserver (requires same uid)

  • kwargs – parameters to pass through to super

_image: str
_name: str
_user: str
_port: int
_packages: List[str]
_client: docker.DockerClient | podman.PodmanClient
_id: str
_containerdir: str
_dockerfile: str
_has_not_apt: bool
_rm: bool
_ex: bool
_forward: Dict[str, int]
_symbols: bool
_i386: bool
_template: str
_containerhome: str
_lockfile: str
_type: str
_native: bool
_native_ok: bool | None = None
VAGD_PREFIX = 'vagd-'
DEFAULT_USER = 'vagd'
DEFAULT_PORT = 2222
DEFAULT_IMAGE = 'ubuntu:noble'
DEFAULT_PACKAGES = ['gdbserver', 'python3', 'sudo', 'socat', 'openssh-server']
_cap_add = []
_privileged = False
_create_dockerfile()
_create_container_instance()
_build_image()
_vm_setup() → None

pass

_vm_create()
abstractmethod _client_setup() → Any
_init_pid() → int

host pid of the container’s init process

static _status(pid: int) → Dict[str, str]

parse /proc/<pid>/status

_host_pid(pid: int) → int | None

translate a pid inside the container to a host pid

Parameters:

pid – pid inside the container

Returns:

host pid or None if not found

_child_pid(parent: int, tries: int = 200) → int | None

host pid of the first child of a host process, polls while the child is spawned

_native_supported() → bool

check if the host gdb is allowed to ptrace processes inside the container

process(argv: list[str] | None = None, socket: bool | None = None, native: bool | None = None, ulimit: Dict[str, Any] | None = None, **kwargs: Any) → pwnlib.tubes.tube.tube

run binary in container as process

Parameters:
  • argv – comandline arguments for binary

  • socket – override the instance’s socket transport setting

  • native – ignored, only relevant for debug

  • ulimit – override the instance’s resource limits

  • kwargs – pwntool parameters

Returns:

pwntools process

debug(argv: list[str] | None = None, gdb_args: list[str] | None = None, gdbscript: str = '', sysroot: str | None = None, sysroot_debug: str | None = None, socket: bool | None = None, native: bool | None = None, api: bool = False, ulimit: Dict[str, Any] | None = None, **kwargs: Any) → pwnlib.tubes.tube.tube

run binary in container with gdb, attaches the host gdb directly if possible

Parameters:
  • argv – comandline arguments for binary

  • gdb_args – gdb args to forward to gdb

  • gdbscript – GDB script for GDB

  • sysroot – sysroot dir (ignored for native attach)

  • sysroot_debug – sysroot debug lib dir (ignored for native attach)

  • socket – override the instance’s socket transport setting

  • native – override the instance’s native attach setting

  • api – if GDB API should be enabled

  • ulimit – override the instance’s resource limits

  • kwargs – pwntool parameters

Returns:

pwntools process