# Trail of Bits Workshop | Josselin Feist | Slither: introduction to custom analysis  | ETHDam 2024

- Speakers: [Josselin Feist](https://streameth.org/speakers/josselin-feist)
- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 28:18
- Watch: https://streameth.org/watch/yt-8xAWs1Jdn78
- YouTube: https://www.youtube.com/watch?v=8xAWs1Jdn78

## Description

Workshop with Josselin Feist (Engineering director at Trail of Bits) on “Slither: introduction to custom analysis” at ETHDam 2024.
https://twitter.com/Montyly https://twitter.com/trailofbits https://www.trailofbits.com/

James Campbell - MC of ETHDam, Hackathon Organiser, and Web3 Developer.

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 
ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz


We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/

Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

## Transcript

[Music] uh Joseline from Slither thank you it working yes perfect okay hi everyone so welcome to this workshop on slitter um so first thing first who am I my name is Jan Fe I'm the engineering director of the blockchain team at 12 bits if you don't know us we are a security company where we specialize in high hand security technology we work on blockchain cryptography application security machine learning and so on one thing which I think defer us from like other competitor is that we focus a lot of our effort into research and tooling development as a result we have built a lot of Open Source tool you might know slitter which we're going to see a bit more deeper today akinaa caraka Medusa and so on but um today I'm ging this Workshop because we have a price for the araton which is a 2K price based on the best kind of like project which is going to be built on top of s the goal of this Workshop is going to give you a quick insight into how s Works how can you extend it what can you kind of benefit from it and to help you to go through like this this bony we are giving a couple of example of things that we believe you can build in a couple of days with slitter for example we have a new vs Cod pluging which is going to allow people to create custom analysis and custom visualization for smart contract uh you can build onchain monitoring for example you can use litter in a way that uh you can kind of query the different variable State over the time with G different block number um you might be able even to build some kind of machine learning extension where you build a custom kind of uh Q&amp;A Bo with litter and and long chain um you don't need to work on this project but just some example of things that you you can work on uh in term of criteria what we are really looking for is novelty we want to see interesting idea from the project and Reliance on slitter the more you slitter in your project the better it is we also have on critic SL Dam like all the wood we have a couple of API couple of video and and a lot of things to help you getting started okay but here we are going to quickly see what is litter a couple of internals and AP that you can use and yeah how to get started you might know slitter as a common line tool you might have been using slitter to find vulnerability in your code base 90 is% of the people that are using slitter use it that way they just went slitter cut base and they went a bunch of detector the thing is that slitter is actually much more than that it's a full custom bble static analysis platform where you can use all the analysis that we have built for the detector to build new things as we're going to see today um s is open source it has been open source for like I know five six SH now it's in Python um and yeah it's on G as I mention most of the people use litter just from the command line but you can use its python IPI to build any type of tools here is an example of tools that we have built ourself on top of slitter for example um slitter check up durability it's a specific tool to check for common flows we have seen in delegate C based proxy um slitter with storage so this one is tool that is going to connect slitter with LPC node and give you the information of the what like the variable value of the given smart contract which is deployed typically as you might know there is like all the Storage storage layout in a smart contract when you have like a variable at at a specific slot slitter will automatically find out where it is in in storage um another one is slitter check ERC this is just going to try to check if your if your contract is compliant with a given RC rc20 c721 and so on it's just going to apply a bunch of criteria and and check on top of it before I go a bit more further into the API is there any question I cannot see well okay so here I'm going to give you a couple of kind of intuition hints an example into how to use the API and how you can kind of manipulate everything that slitter gives you uh it's in Python so you need a bit of python understanding to give you a really quick uh example of things that you can do on top of spitter so and this is not working oh sorry yeah so here basically you create a s object you open a file you can Reve a specific contract which a specific variable and you can ask S what are all the function in this contract that write to a given variable and then you can print it so you can see with what five line of code you can already manipulate a contract extract some information and and kind of process it so how does it work under the hood what slitter does basically is that it's going to take what it's called the So-Cal IST so abstract sentex tree from the compiler it's just a representation of the code base that the compiler is giving us looks like this it's a where every node is either an operation or a variable take this and do a bunch of analysis and a bunch of kind of recovery of information and on top of that it's going to Pro to provide you five layer compilation unit contract function control for graph and expression intermate representation um and we are going to see what is every layer no uh yeah but first uh yeah something I wanted to highlight you might have H slitter most of the time on a code base you have like a solidity file you have a project using Foundry hard out and you just want slitter on top of it what you can also do is you can provide an address and if the code is on scan will you will be able to directly analyzing it for example in this example on line three or four uh we create a slitter object we pass the address of usdt and slitter is going to retrieve directly the contract from it scan and compile it pass it those and all analysis if you do that in a kind of in a butt or if you do that in a way that you're going to to do a lot of query I would recommend to use a flag scan API key to provide an scan IPI key this is just if you're going to hit some rate limit on scan we support almost all the test net we support bance chain we support arbitrum optimism or like any kind of like atasan like platform you can directly provide the address through S so as I mentioned the first layer that s is going to provide you is a compilation unit what it is it's basically a group of file that was used by by that was used to do one call to the compiler why there is this notion um when you have some compilation framework you might have multiple call to the compiler for example in Foundry if you have some of the some of the file that are be compiled by 37 some of the file that are going to be compile by solid8 the compilation under the root is going to call multiple times saly and every time you are going to get one compilation unit from sler how to access them so you create the slitter object slitter do compilation unit which is straightforward why it matters uh for what you're going to do during the three days it probably don't matter for you because most of the case you are just going to have one compilation unit that say when you're going to look at the API from litter some of the API might not seem kind of straightforward might not intuitive because we have this notion so most of the time for you in this hackaton or when you want to quickly hack on top of it you can just use the first element of the compilation unit array so compilation unit bracket zero and you will be okay if you want something to build something more robust that is going to support any type of platform and any type of uh project you might need to support multiple compilation unit again TDR for you for the three days just take the first element what can you have as information from this so you have the compilation unit you can get all the contracts which is straightforward all the contract from from from the project contract derive this is a kind of like a simplification that give you all the contract that are the most derive in the iner down tree most derive basically if you have contract a you in contract B you in contract C and so on the most derive will be a like the one which is not inherited again typically when you work in a code base with multiple contract you might want to only analyze like what's the end result like you don't care about like the Intermediate one if that's the case you can use contract derve get Contract from name which is straightforward you provide a name it it retrieve a contract object you can also access all the top level object structure enum event and so on um with the event provider to give you a quick example so here we create a slitter object we pass the USD address we take the first compilation unit and we just print what are like all the contract what are all the contract derived this is on usdt and if you print that you can see here the difference so here you can see an example of contract and contract derive while the second line is contract dve the first one is all the contract typically erc20 in usdt um doesn't appear in the dve because it is inherited by the T token is pretty straightforward you have t token which inherit from erc20 any question so far okay we have only 30 minutes so I'm going to go as quick as I can but I also want to make sure you understand like the different step once you have the contract object you can query a couple of internal things for example the name which is straightforward inheritance so this is going to give you the list of The Inheritance or the list of contract which are inherited from this contract you can go the other way I want you can call derive contract it's going to give you from this contract all the contract that derive from it so you can basically go both way in The Inheritance Stree um you can get yum event structure again like all the different things that you can get access to in a contract on the variable you can get all the state variable of the contract you can also follow the order of Declaration if that matter for you get function from signature it's going to retrieve a specific function based on the signature pretty straightforward simple example again on other the example U I'm going to reuse always usdt as as as an example so the first line are always the same what matter here is the one in the white box so what we do we fetch usdt contract um we take the usdt token so T token and we print for this contract all the state variable again five line of code and you can see you can already play a bit with with like the API and this is all the state variable in the usdt control okay then you can go one step further so you can look at the function from the function you have the solidity signature pretty straightforward entry point is a nod so not we'll have a couple of example later but basically you can have a graph representation of the function where you can have like all the different operation of this function and you can kind of work through them the different element expression variable modifier a couple of helper that might kind of speed your your your your usage uh you can get all the variable local or state that are read or written so for a specific function cter in one command can give you an information about everything which is read or written all this function can be prefixed by all if you do that you do a recursive lookup over all the internal call so for example if you have a function and you just want to know what are the state variable R by this function but you don't care about the internal call of this function it's just a state R State variable right R sorry if you want to do it and you want to consider what is inside the internal call just add the prefix all before to give you an example here um we are looking at the same usdt token we are looking at the total Supply function and we are asking slitter to print all the state variable that are read by the total Supply function three St variable um now if we want to kind of understand a bit better the difference between having or not the all kind of prefix so we do the same but for the transfer function and we print all the state variable that are read by the transfer function and all the state variable that are read by the transfer function and it's in you can see like is difference and the reason for that is that if you look at the transfer function of usdt there is two internal call one not pause which is modifier and a call to Super so basically here depending of what you want if you want just to look at the function itself or if you want to look at the function and and it's inner U it's going to be important to use a proper API okay any question so this is a workshop I was hoping to have a bit of table for you to play around with it um but we have a couple of exercise to try slitter on so if you go on secure contract.com program analysis slitter you will have the first exercise it looks like this where basically we are going to try to use a slitter IPI to manipulate the code let me zoom in you see yeah so here our goal is going to create a python script that is going to go over the contract and try to implement uh an overwrite function protection so basically the algorithm is here so you get over the contract you iterate over all the different one once you find the correct contract we just check if the mean function has been over written or not see the time um how many of you have a laptop a couple so I'm going to give five minutes to try this and in five minutes I will give the solution yeah so secure contract.com I should have made a QR code it's on me and if you go in Secure contract there is also like an API page and I don't have internet but if you go on the API page um you will see a lot of example and you will see like a lot of uh hints on how to use it yeah sorry excuse me um do you use this SDK for the slicer tool or is it kind of another tool that you propose so slitter is is built on top of the API basically when you use it like from the command line under the hood uh we are using all these different function and all the different things um for example all our B detector so we have like something like 19 each B detector are built on top of this API okay so everything is right on on python right yes okay thank you for [Music] hi uh could you explain who is going to be the user of of the SDK in the way that you explaining it now is that developer who is developing the project and you just want to write an alternative test uh or it's auditor that's a really good question so I think most of the time it's going to be security researcher where they're going to build either custom detector custom script or or things like that um typically for example during a Security review we might have a need to build like a custom analysis just for like the purpose of of of our client U so most of the time we do it U let's say a developer might also you know try and build its own like kind of confirmance tool or like analysis um but most of the target is more on the security researcher side or developers that are a bit more advanced with this type of techniques and I have a feeling that it's going to be useful for big projects and when there's like ton of functions and like that if you have a small project that's like overhead to write actual like thing you want to test to check right I mean it depends it depends because let's say you write a library right like a small Library like you know 300 line of code and you want to make sure someone is going to use the library the way you anticipate it to be used or you might just build custom script on top of it and provide the script as a way for people to test um so it depend but if you write like anc20 token and that's all you WR yeah probably that's Overkill so it depends for company like what what we have seen also is that for example people might want to inv to kind of enforce specific style or inforce specific kind of like a pattern for example and the second example the second exercise going to be about that like let's say you want to have a wh list Bas approach for your function all the function need to be Nam U I don't know like uh something something otherwise they to have a modifier with an access control and this type of things you can programmatically unfor them with lter and you can say okay like all the public function have either a modifier or are within like this list of name does it make sense yeah that makes sense I have a feeling that I can use it like a pretty fire uh you can also do it like that like to build to incorporate it with like cicd yeah and like run it all the time when I have a p request something like that yeah we actually have a slitter action so it's a GitHub action that you can plug into into your CI uh which is going to one all the detector and and everything related okay um has anyone managed to find a solution for this one okay but basically it would looks like that so once you have the C object you can iterate over all the contract um and what you're are trying to see is that you trying to see if the function was over rden by another contract so it's just algorithmic it's just you iterate over all the contract you get the you get the function you check if the function declarer is the One You're Expecting if it's not it means that someone has override this function um so exercise that you can find on secure contract I'm going to go quickly for the sake of time but it's kind of like the same idea here what we're are trying to do is that um it's kind of what I was hinting um let's say you have like a code base when you want to impose a specific style for your access control and you want to say okay all the function of the only owner modifier in this contract except A and B um you can use litter to create this type of kind of script so basically what it would looks like let's say in your contract in your code base only balanceof doesn't need to have only modify only owner which is sounds quite straightforward um then you can explore the code base you can explore all the function and just check if the function visibility is public or external otherwise an internal function and check if it's within uh the white list that you have created like the code mostly here is like generic python script you just iterate over the function check if your function is in the white list does that make sense as you can see because it's in Python you can pretty much develop any type of logic you can develop any type of kind of application and slitter give you access to all this information for for free yeah then for the third one um this is a bit more kind of a specific use case that you might have in particular when you do a Cod review you want to find which function use a specific variable in a condition condition can be requir can be like you know if than else when you do like an audit when you do a code review sometimes really important to be able to say okay how this function is how this variable is used how how in the code base it's going to influence and impact and condition it might be something you want to look for to do that um again it's kind of straightforward with the API you can get the variable from the um contract object then you can check if this variable in in which function this variable is used in a conditional node or in an assertion require um I'm not sure you can see it yeah it's big big enough um but yeah basically in a couple of line of script you are able to implement this type of tool this type of specific need um so yeah from from like a security researcher perspective this kind of speed up your process significantly any question okay something that we release yesterday in time for the hackaton so we released a new vs Cod plugin that ches slitter as the backand the way it works is that we have an LSP server if you're familiar with that basically just like a standard uh form for for code Explorer what it does is that it's going to allow the vs code plugin to communicate with slitter and to receive all this kind of information and and and provided API so the vs code plugin can do things like go to implementation go to uh definition find all the reference show show like the call and type hierarchy um for example here you click on on a modifier and it's going going to show you like the call hierarchy of the modifier pretty standard for most of the common language to have these type of things for solidity it's either lacking or it's kind of lacking in work in progress so we have developed the pluging to do that um it's really easy to HCK on top of it you can find the link in the it Dam weo to where basically you can just had any type of Handler on the LSP side so on the server side the backend side and just develop an interface an interface for it this is an example of things that you can probably if you're interested ha on top of bring this ha Kon and it's cover within the the B so where to starts um secure contract as I already show we have a bunch of exercise we have more detail about the API more detail about how to use it and about static analysis if you clone the GitHub from slitter we have slitter tool demo weo directory sorry where you find a bunch of kind of um default passing argument and just everything to get started much quicker if you instead of starting from scratch you can also take a look at the slitter detector a code base just to get a sense of the API how we use it in a more efficient way what we can build on top of it and so on and yeah so as I mentioned slitter is an open source framework you can build any type of analysis on top of it we have the hackaton with a 2K price you can scan the QR codes to go into critic each has done we have uh a Discord Channel 12 bits you can also ping me directly on on Discord we have a GitHub a slack if you have like further question after the any question any final questions for Joselyn yeah yeah thank you um I just have a question more about sler um so from my understanding it's kind of a ass sast tool so static analysis component and do you do also SCA analysis from I don't know from libraries from I don't know open Zing that have some vulnerabilities on it EAS your tool can um I don't know manage that and a warning also yeah so here I I show slitter from like an API standpoint but it can also be directly out of the box use as a common line tool and if you use it as a common line tool you going to get access to all the detector that we have already implemented and if you do that uh yes you can directly find vulnerabilities and we have something like 90ish detector that have been built based on what we have seen during our different Cod review and audit okay and about that um I'm also interested about um kind of the database that going to say okay this um package is vulnerable for for this one um do you have kind of open database for that I mean how not not at the moment but it's something we are considering okay thank you thank you very much that was excellent [Music]
