ETHDam - Trail of Bits Workshop | ETHDam 2024
CryptoCanal·Mon, Oct 7, 2024, 12:00 AM
On April 4th, we hosted an online pre-hackathon meeting in preparation for ETHDam. This sesion aimed to introduce Trail of Bits and teach us how to use their products and tools so that hackers can choose what to implement in their projects and make informed choices. ETHDam 2024 - April 12 (Friday) to April 14 (Sunday). An in person 3 day Conference and hackathon gathering the best Privacy and Security builders at Pakhuis de Zwijger in Amsterdam. https://www.ethdam.com **************************** Hacker's Program: next up: OASIS NETWORK WORKSHOP: On April 5th, Oasis Network will teach us how to use their protocols, products and tools. https://lu.ma/ETHDamOasis HACKER SPEED DATING: Team building and project ideation, April 12th at 11am CET. ETHDam. https://lu.ma/HSD HACKER SPEED DATING ONLINE SHEET: Before the Hacker Speed Dating IRL workshop scheduled for the first day of ETHDam, feel free to begin forming teams online. https://docs.google.com/spreadsheets/d/1rzb2-KB-NB1rlMAIuzEmztpzW23LU6zBYAFqlA-6aNo/edit#gid=0 DISCORD: Join the Discord channel dedicated to the hackathon. Present yourself, get familiar with the channels. Find other team mates to hack and have fun in Amsterdam. https://discord.com/invite/BXyxqWDF2E **************************** Hackathon Bounties Get ready for some exciting bounties from our hackathon partners. Hackers, do your homework, get familiar with each hackathon partner and go through their technical documentation. Battleship: Oasis Network (12K) https://oasisprotocol.org/ JetSki: NEAR (6k) https://near.org/ Canoe: Waku (2K) https://waku.org/ Canoe: Trail of Bits (2K) https://www.trailofbits.com/ Canoe: Threshold (2K) https://threshold.network/ Canoe: Privacy Scaling Exploration (PSE) https://pse.dev/en MACI (2K) https://maci.pse.dev/ TLSNotary (2K) https://tlsnotary.org/ Semaphore/Bandada (2K) https://semaphore.pse.dev/ More info about the logistics and the hackathon in our Hacker Handbook. https://docs.google.com/document/d/1wpQ7XYZE5wTUW5wRCzHPaHNYfsh16xUPwf6WvlbuZlc/edit#heading=h.elpadkljt387 **************************** CryptoCanal will host its second edition of ETHDam, a conference and hackathon held this April 12-14 2024 in the heart of Amsterdam, in the Netherlands. They will gather more than 600 participants, bringing the best Privacy and Security builders in the cryptocurrency industry.
Transcript
[Music] welcome everyone tuning in for this trailer fits Workshop thank you all for coming hello hello welcome to this trailer fits Workshop um we're being all very punctual today but nice to see you all um I'm Elanor I'm the main organizer of etham you'll see me walking around uh during the conference in hackathon I'm the the pregnant lady so you can't miss me with purple hair but I really look forward to welcoming you all uh during eem in a week from now which I can't believe we're already at this point um but I'm really happy uh that you're all here today curious to learn more about trail of bits um they will be a canoe sponsor for uh etham and they will have a 2K Bounty uh to offer to all of you so this is really smart of you for all of you to join uh this etham boot camp um we want to make sure to give you as much information in advance for you to learn as much as possible today um I'll give the the the stage very fast to to Jon for him to to tell you more about tra of bits itself for anybody who wants to stay on after the workshop uh we'll facilitate as long as you want it if you want to do a bit of team building if you want to get to know other hackers um yeah thank you so much already for tuning in and without further Ado Jocelyn this is your time to shine thank you for the introduction okay let me share my [Music] screen and let me Go full screen okay um first question first can you see my screen yes I can see your screen perfect okay so welcome everyone welcome everyone to this presentation on sler so during the araton at it Dam we are going to have a 2K priz for some of the best kind of project built on top of slitter so we wanted to take the opportunity of this of this Workshop to give you some kind of work through of our IP and how to use lit what it is what you can do so that you can be a bit equipped before Theon to understand kind of like the capability of the Tool uh but first thing first who am I my name is jna Feist I'm the engineering director of the blockchain team at trade of bits if you don't know us we are a security company where we specialize in high hand security technology uh we work on blockchain but we also work on a lot of different aware such as traditional application security cryptography machine learning one I think of kind of specificity is that we specialize a lot in program analysis and we always try to apply research in our day-to-day activities as a result of that we have built many open source tools that you might know such as slitter ainina Medusa caraka and so on uh but as I mentioned today we are going to focus on slitter and the reason for that is that we have a 2K price for slitter aaton so during this presentation we are going to see what is L we are going to see it's internal it's API it's intermediate presentation and really the goal for you um is at the end of this presentation you will be able to have some high level understanding and some kind of points on how to start how to build on top of s what you can do what are kind of like the capabilities feel free to stop me at any time if you have question this is going to be a bit Danse it's going to be a technical work through of of the capabilities uh so if you have any question I can stop and you know this can be interactive if you if you have any need for that okay I've been talking about slitter for one minute now but what it is you might you might have used slitter in the past as solidity developer or security engineer slitter is a static analysis framework for both solidity and Viper what it does is that it provide um a lot of analysis that are kind of out of the box such as vulnerability detection optimization detection but it goes be on that and it allows people to kind of improve their understanding of a code base and it allows kind of custom API to build additional tools on top of it SL is open S it has been developed for probably five years each now um and you can see the card here it's on python um top there on a really really high level if you think about slitter uh its architecture is kind of close to a compiler the way it works that it's going to take the output from a compiler solidity compiler or the Viper compiler is going to do a couple of info and kind of a couple of analysis on top of it to retrieve some information to build its own intermediate representation which we are going to see later it does a couple of code analysis to kind of find some information and it provide all this information all the result of the different analysis to the different module from vulnerability detection optimization detection printers and kind of third party tools so so I think 90ish per of the people that use S mostly use it from the command line to find vulnerability if you have used it in the past you might know that it comes with inbuild detector so right now we have more than 90s public detector that are available for everyone from high severity to optimization uh it really run from everything we have found during our Security review and our audit and we are kind of constantly improving the detector SL as a proven track of vulnerability fonts just by using the tool you can see the slitter trophy page on our GitHub where we just list like some of the vulnerability that we know about that we F just using the tool through this presentation I'm going to give you a couple of kind of cheat sheets just to understand some of the most common command line most common API for you to use when we talk about detector the first one to know is L list detector basically just it's going to just show you like all the detector are available if you wants to run specific detector on a Target you just run slitter the target Das detect and the detector name which is straightforward one thing that you might know is that all the vulnerability that are going to be found by spitter might not be real vulnerability you might have kind of false alert or false positive so part of the work when you use litter in a Cod base is to Tre result of the detector to do that there are a couple of techniques the first one is to use code commands in solidity to disable the detector so the first one slitter disable next line you just disable the next line for a specific detector you can also use it from like a code command where you have a start and an end I'm going to give an example in the next slide and if you want to triage some specific vulnerability such as reany we have a couple of additional technique such as using custom NP command I'm going to give an example in a few so here we have a piece 3T code there is a Rey vulnerability in this code and let's imagine you don't care about this vulnerability and you don't want lter to one about it here you can use a code command where before and after the function you declare slitter disable start slitter disable end with the name of the detector so this is just going to tell theer to not report any reentrance in this function obviously don't do don't do it on on a will POS on a will vulnerability but it's just to give you an example on how to tr it I did mention that we have kind of custom common for some of the detector in particular for reany so when you kind of start to triage reany alert on a large code base you might end up in a situation where a lot of for positive comes from a contract or like a variable which can do external call but you are kind of sure that this external call are not going to be reant for example if you have an rc20 token and you call the transfer function depending on the implementation of the rc20 token it might have external call or not within the transfer function if you know that the contract is not reant you can add kind of this custom comments uh right before the Declaration of the variable to tell slitter this is not a re contract you don't need to prevent you don't need to tell me abouty related to this variable another way to tr the result is to use the interactive mode so slitter the target d d mode this is going to create an interactive mode where for every vulnerability you can discard and kind of create a database that will kind of include all the things that you have Tri so that every time you run slitter you will kind of discard the thing that you have already kind of treed this is useful for example if you run it for the first time you discard everything which is not relevant and then you can keep running SL on top of it now the best way from a developer standpoint to do the triage I think is to use a gab action that we provide which is also open source uh which is integrated Within ithub so as you can see in the screenshot you have Cod scanning from GitHub you have like a nice interface to triage a result it's just a bit kind of easier to triage SL result through GitHub than through the command line um in addition this can be included in the in the P request process so you can have S outs on every pool request and give you warning when there something happening one kind of features and flag that is also useful is a filtering pass so here you can tell SL to ignore specific file or specific directory under the hood is going to use Python regular expression this is going to be usefully for example you know that there is a directory with Mark Contra and you don't care there's like vulnerabilities in the mark Contra so you can just T to ignore this pass with Filter pass when you run slitter you need to provide a Target and this is where I think a lot of us are sometimes a bit confused and don't know exactly how to navigate this the target needs to be something that can be compiled the first US of it is to run slitter on the solidity file so SL file. Sol um this is okay but it's not the most recommended I'm kind of way of using it because from the moment your compilation will require real mapping it is going to be a bit tricky and you might need to add additional flag U kind of like the idea is that if you can run saly with a file you can run s on top of it but if just by running directly on the file it doesn't compile most likely SL is not going to be able to compile it out of the box without additional remapping here the kind of recommended version is to use compilation framework which most of the people are using where Target is not a file but you are kind of analyzing but the root directory of the project for example if you on a fundry project or ar or trle or you just need to run slitter on the top directory if you are running slitter from the top directory directly you just 1 lit dot dot being the current pass we do have a couple of extra support for Foundry so if you are on the top directory and you want Foundry with a solidity file s going to try to figure out the mapping automatically with Foundry but sometime might not work depending on the complexity of your mapping another feature that I'm not sure a lot of people are aware about slitter is that we can directly analyze contract at our deploy as long as the code is a scan or an any a scan like platform to do that really simple slitter and instead of providing a file you provide an address this support most of the test net most of the layer one layer two that are evm compatible for example we support arbitr we support Optimus binance Bas and so on you just need to say slitter the kind of keyword of the of the network and the address that you can kind of once L directly on top of things that are Deploy on chain as long as the Cod is verify on scan or scan like platform okay before I go to the kind understanding is there any question getting the detector we do have a question in the chat okay let me try to find this the question is oh go ahead so the question is does L works with a diamond standard working with diamond and facet yes it works out of the box on any kind of like standard platform as long as it solidity we don't have a specific support for Diamond standard uh but we can analyze the code base without any problem uh where so the second question here is where does s t come from um that's a long story but short we started with solidity analyzer then we want to have something related to animals or mythology um and that's where we ended up with something related to uh a snake and S okay so question next question um target audience is it useful for all level of developer I think it's useful for all level of developer part of the presentation is going to be a bit more a deep dive so it's probably going to be more useful for intermediate developer uh but first kind of half of it might be everyone okay next question what do you expect from us doing each asham um so we're going to have an araton and what I would kind of invite everyone to try is to try slitter and to build a project on top of it we are going to give a bit more details about the theme that we are looking for people to work on uh but it's going to be things like integrate slitter in some kind of interface or kind of combine slitter with machine learning or these type of things but more details to be to be to be um Shar soon okay next question does ler contract verification D work with block Scout light Explorer to that's a good question I'm not sure we support block codes um but we could have the support so basically it works with any kind of scan like like platform any kind of web interface where you have the source code and we can quate it we can also support for it so for example we support as I mentioned arbitrum like the arbitrum Explorer the uh optimism Explorer the binance one I forgot the name of the of the Explorer and and so on where do you get the for from the Explorer they are hardcoded um in in stto yeah if or this is not we can definitely add it but it might already be there um to be confirmed okay I'm going to go back to the presentation okay um so as I mentioned I think 90% of the people use lit just through the detect but we have actually a couple of additional features the first one are the So-Cal printers so printers are visual representation of the code and we have kind of a bunch of different visual representation the one you are seeing on the right side here is inheritance graph if you have worked with complex solidity code base you know that developers tends to even use inheritance and you end up in a situation where contract a inherit from B inherit from C in fromd and it might be difficult to navigate kind of The Inheritance tree of a code base so here is where kind of like this visual representation can help we have other one such as a human summary which is going to give you like a really high level summary of of the contract is it upgradable or like does it follow any a and so on we have a couple of them that are a bit more in depth that a bit more kind of complex for example vs and O is going to give you a table with all the variable and the different authorization and control of a function so for example if a function with some like a specific variable and has an early owner modifier it's going to highlight it similar to the detector to list the printer you can just run slitter list printer and to run a printer on a Target slitter Target Dash print and the printer n which is straightforward okay but the part where I want to go today is really more about not using slitter from the command line but using its API to build tools and to kind of hack on top of it and this is where slitter being a generic static analystic framework is going to be useful so when I say generic static analysis framework slitter is basically a tool on top of it on top of which you can build a lot of things and here is just a couple of example of additional tools that we have built are also open source and comes with lter that just rely on this API for example slitter with storage so this is a tool that is going to is going to allow you to read the value of a variable on chain and the way it works is that SL is going to query the source code for example on the t scan it's going to figure out what the storage layout of the contract and it's going to query on FPC not to get the value so this is like an example of kind of API that you can build on top of of slitter we have other things for example slitter checkup cability which is a specific tool to riew delegate call Bas proy vulnerability um due to the upgradability we have also cter check herec you give this uh contract and it's going to check forc confirmance ERC confirmance for example if you say okay I'm building an erc20 it's going to check if you have like the proper function if you return the proper parameter and so on so it's kind of like a confirmance check but as I mentioned all of these tool were built on top of ler using the python API and what we are going to see now is how you can leverage yourself this API just to give you a really kind of quick example if you want from a code base to know what function can modify sorry can modify a state variable you can do that in five line of code here you provide solidity F you can of work through the contract the name of the the name of the variable and you ask slitter what are the function that can write the specific variable and slitter is going to thank you okay so how does it works and how can you kind of lever at that U the first things to understand is that as I mentioned at the beginning slitter takes as input the IST from the compiler IST is an abstract syntax tree it's a common representation of the code bys that the compiler both salty and the Viper compiler provide just to give you an Insight what does it mean if you take like this solidity code the representation is like the uh Tree on the right side it's basically just going to have like a every operation is going to be a nod and you can kind of work through that and the leaf are going to be variable in kind of simplif simplification this is a really common kind of representation in in static analysis from that slitter is going to provide a couple of layers that we are going to see now basically uh five layer compilation unit contract function control for graph and expression SL intermediate representation the first thing that you have to do is that in Python you have to create a slitter object to do that you import or from slitter import slitter the slitter object and you create by providing the Target now the target here can be anything that we already described on the detector pass it can be a file it can be a project or it can be a contract which is on chain for example here you can see kind of at the the middle of the slide um I'm creating a St object where the address is the address of the USD token on Main dat some things to know is that if you start doing that on a boat or if you start doing that you know like you run it a lot of time because it query a t scan you might end up reaching the scan key limit so you can also provide to the slitter object an scan LPI key which is just going to allow you to make more queries so scan IP is free but you need to register on scan this is just if you do like of query to different contractor if you build a but um you will probably reach the right limit of a scan okay the first layer that we're going to talk is a compilation Unit A compilation unit is really a group of files used by one call to the compiler most of the time most of the targets that you going to analyze will have only one compilation unit but it's not always true because depending on the compilation framework you might have partial compilation for optimization so maybe it's only going to kind of analyze a couple of files or if you use multiple salty version for example with Foundry if you have like one 3 dt5 with 3 DT 0.8 and one other with 3 DT 0.7 this is going to create multiple call to the compiler so this is going to create multiple compilation unit how to access them you create a s object with a Target and then you can do the object do compilation units which go turn an hour why does this matter because when you're going to go through the API from slitter some of the API might not be intuitive because of this notion of compilation unit it's something which is needed from from from the architecture standpoint but might be a bit confusing at first for example if you if you are looking for a contract based on a name you can actually have multiple contracts with the same name and frequently if you have like multiple compilation unit but this is something to keep in mind however if you are hacking on top of L if you're doing like a quick concept and you just want to be you know really fast you can probably just assume there is one compilation unit and from the AR just take the first element so SL object. compilation unit and you just take the first element which is at the zero offset now you have this compilation unit object and you can do a couple of things the first thing you can do is that you can list all the contract from this compilation unit the second one which is contract derve here it's going to list all the most der contract so most day contract is a contract which is not inherited anywhere else in the code base this notion is important because sometimes you want to kind of explore all the contract of a code base but sometimes what you really want are all the leaf in The Inheritance tree because it's usually where you have like most of the logic which which is implemented another function which is useful is get Contract from name which is straightforward um then you can also access all the top level object structure any EV V function top level follow solidity in the sense that these are like the object that are not declared within the contract they are declared outside of the contract to give you an example so here we are creating a s object with the usdt address and then we print all the contract that are this address and we also print just after that all the most DF contract and if you run this you will see like the two difference like the first one you have like a lot of contract and if you look at the most you only have three of them for example ec20 or20 basic are going to be inherited by the T token as a result they are not in the most wife contract so here if you look at the code base which is deploy um you will see like save mat upgradeable upgrade standard token and dat token are the most derived one okay then we can go one step further so from the compil unit we can start exploring the contract from a contract you have a couple of method that are going to be useful for you the first one the name which is straightforward then you have the inheritance so the inheritance is going to go in both side directly inheritance it's going to be all the contract that inherit that this contract inherits from something to consider that here we follow the C3 linearization order if you don't know what the this is if you don't know what the C3 linear ation order is I highly recommend after this presentation to look it up it's basically the way solidity is going to deal with multiple iner return it's a concept which is important if you kind of want know to to to become a bit more advanced in solidity let's say just here SL just follow this order the wife contract goes the other way around you can know which contract are going to inherit from the one you are looking at so basically you have an irritance tree and you can go back and forth in in the tree you have also a bunch of General object enum EV structures so the one are this one are the one that are declared with the contract now for the state variable here you can directly access State variables which is going to be the list of accessible variable accessible because within solidity a contract might inherit from another one which has private variable private variable are not accessible from their wife contract so you will not see them again like here we are trying trying to follow um like the solidity convention if you need to access everything you can access them with State variable order which is going to give you order variable order by the Declaration finally get function from signature U yeah pretty straightforward these are just some example of the API if you go to the contract.
pi or if you go to the documentation you will find other IPI but at this one give you kind of like the B thre to build on top of it so in the following example every time there's kind of a red box it means that everything above is just the same Cod on the previous example so like the first line is to impers L second one to kind of create an object from the usdt contract and the compilation unit again same thing that we were doing before now the difference here is that we are printing from the T contract the US contract all the state variable and if you run this you will see that so this is all the state variable on the USD contract I think you can already kind of have the inside that's in know what five line of code you can start playing with um with some of the information on the realt contract so you can start kind of building on top of it and you can start navigating what are the variable what are the contract and doing back and forth with that now we can go one step further so we have contract we can go into function um some of the IP that are going to be useful for navigating with function are here the first one solidity signature pretty straightforward entry point which on a node we are going to give a bit more details about what's a node and the control for graph in a few but just to give you kind of information that this is already accessible from the function elements you're going to have expression variable not modifier of the function then you have a couple of operation that you can access from the function for example you can access all state or local variable that are read or written so if you wants to know like is this function with withing a specific variable or writing a specific variable both local or state you can you can access this just with this kind of function all all of them State local with right can be prefixed by all if you prefix them by all it basically does a recursive look up in the sense that instead of just looking at the scope of the function you are going to look at the scope of the function and all the internal codes I have an example just after just to make it a bit more clear and additionally you can over the S higher operation which we're going to see later so a simple example again the line the first four line exactly the same as before ref fetch the USD contract we F the USD contract so now what we are asking is that we are asking to print all the state variable that are read by the total Supply function and to do that we call get function from signature the signature of total Supply and we just print all the state variable that are R if you do that yeah basically three St varable are on USD total Supply function but as I mentioned we have kind of for type of operation we also have a version with let's start with hold that you can see here like the first variable the first the first print operation is going to print all the state variable that are read by the transfer function and the second one exactly the same but including the inner call if we look at what is kind of show here is that here when you run this piece of code um you can see that the version that is recursive with the internal code does show a lot more variable so reason for that is that if you look at the transfer function on usdt it has two internal calls the first one is a modifier when not pause and the second one is a call to the superare do transfer function kind of like the idea the idea here is that based on what you need you need to use a proper IPI if you just look at the of the function and you don't care about what's happening in the in the uh internal call you can use a normal API if you want to have something a bit more Broad and consider everything which can be done by the function and its internal call you can use all underscore the name of the of the property okay next concept kind of to it's going to be useful for any any static analysis is a notion of control for graph control for graph is a really common code representation for static analyzer and compiler basically you take your code and you represent it as a graph nothing nothing magic here um you can see the example on the on the left side and on the right side here there is no there is no Loop there is no if there is no there is no for Loop if you have a for Loop you can have a edge that comes from like one point and go back to to to like to Inner node uh basically it's a control flow graph because it's a graph that represent what are the different control flow of the code control flow being condition Loop and so on um why this matter is that depending on what you're going to do is that if you want to build complex analysis you will need to iterate over the node of the control F graph if the order of what you are doing doesn't matter you can just iterate over the list so you have function. node which is a list of all the node you can just do for node in this list now if you start building more complex analysis where the control flow is important you need to you need to work through the node here I just give kind of a snippet of cod which is a kind of a standard way to work through the node um using a visit kind of pattern so you define a Noe where you you you you want to kind of explore the no that you have already visited and if you if you never if you already visited them you just stop if not you go uh do some custom action and you Rec serly call the same function overl the sun of the N so overl the node that are after this one in the control for graph now if if you start building complex analysis which uh is going to require a bit more kind of consideration uh you might need to you might you might need to iterate multiple time over over the not in a control for graph so here you have to be careful because now because you are kind of iterating overall graph you can have an infinite Loop like you can go over and over and over and never finish to avoid that you have two strategy the first one you just B the iteration and you say I'm going to recursively call this function with this parameter until some time or you can call you can create a so-call fix point where basically you can say uh I'm iterating until I'm not propagating any new information which is kind of similar to abstract interpretation or like more traditional control flow analysis if you are familiar with that again here it's really more if you are kind of going into complex analysis um if not you can just discard everything I just said okay before I go a bit more into detail into the intermediate representation is any question okay let's go over the intermediate representation so what is an intermediate representation it's a code R representation that is usually used for code analysis purpose so you can consider that for example solidity is a high level language used by human you are going to develop your code in solidity stire or Internet representation goes a bit lower and it's its purpose is to make the uh the creation of card analysis simpler to do that we have design or intermediate representation with a couple of things in mind it doesn't have a lot of instruction so we have less than 40 instruction it's a linear interm representation there is no jump uh and the kind of control for graph is based on the slitter control for graph in that sense if you're familiar with intermediate representation it's a hybrid intermediate representation it's a flat intermediate representation in the sense that there is no nested operations if you consider solidity you can have nested expression for example you can have an addition of an addition of an addition everything is in the same line and this is nested in three Tire everything is flat so like if you have multiple operation it's going to be split into multiple operation in that sense um we do a lot of cut transformation simplification for example in Sol you have a ternary operator we are going to convert this into an N mostly just to again like the purpose here is to make the creation of code analis simpler so we have made we have made a couple of uh choice in the design for that to give you a quick kind of intution in how like interm intermate representation looks like we have binary and unary operator like for example addition we have index for mapping access we have member for structure access we have a bunch of new operator here we can see that for example we have a new structure operator which does not really exist in a kind of explicit way and solidity we made it explicit just so that it's easier again to build analysis on top of it keep in mind that again this is like this inter representation is not meant for people to read or to read it's really more for the analysis to be easier to build on top of it to give you kind of an example if you have like this in solidity allowance of form of message center and you decrease by value this will create three operation two def variant and one uh subtraction something to keep in mind when you're going to play with intermediate representation is that we have kind of achy in our class um this is just kind of a subset of other the operation but you have here some representation where you have operation at the top you can have a condition you can have an operation with L value I'm going to go over that in a few and you can have call operation with L value L for left is basically an assignment so any operation which inherit from from this is basically going to be an assignment like binary operation mber high level call high level call is basically an external call to another contract so here it's a good example where High LEL call is both an assignment so an operation with L value and also call in comparison to that event call which is Operation when you create an event doesn't have any assignment so it's just a call okay now when you want to manipulate the intermediate representation a couple of things to consider um the first things usually to do is to check if the operation you are manipulating is based on a specific type so you can use his instance in Python to do that for example is instance inter representation of a call if you want to check for example if the operation is an addition you first check with e instance if it's a binary operation and then you check its type to see if it's an addition if you want to check if the operation is a call to my contract again the same you start with is instance is it an I call and then you check if its destination is my contract here something important to consider is that every intermediate operation is going to have its own set of methods so for example destination which we use for high level call doesn't exist for binary because binary doesn't have destination um so here it's important to go through the documentation for every operation you want to manipulate to understand what are kind of like the capabilities to give you an example here so again like the first five line are the same as before we fetch reality contract we F the total Supply function now we iterate over all the inter representation and we look if there is a high level call high level call again is a call to an external contract and if there is we just print it if we do that um we will see that yes there is a high level code in the total Supply function and and it provide like the source mapping something I I went quickly over here is that if you look at the last line on the print and the kind of like the part in parenthesis you can see IR do not. Source mapping this is just kind of a shortcut that is going to allow you to map back the inter representation to the solidity Source mapping so here you can see there is like T token do Sol and the line number so this is usually useful if you start haing on top of it to understand where it's coming from there are a couple uh featur a bit more advanced you probably won't need them but I'm just going to quickly uh mention them so that you are aware in particular if you go through the source code the first one is a notion of SSA so SSA stands for static single assignment it's basically another inter presentation where every variable is assigned only once this is really important for the internal off slitter we use it to build some of the analysis and it provide it allows to create more precise analysis however it might not be kind of needed for you second things I wanted to mention is that we do lightwe IAS analysis on the storage reference so if you have like for example a function with a parameter which is a storage U the storage like the multiple variable might point to the storage and we do an analis to determine what what variable can it be uh so this again it's more if you start to play around with more complex analysis and you need to to kind of determine like some some complex pattern okay before I go through the data dependency there any question okay the data dependency is another feature that is a bit more advanced um but is is useful to understand that this is available in particular like if you want to think a bit more long term about what can you build on top of slitter knowing that this is is available for you is probably going to be useful data dependency is basically a way for you to know if a variable is dependent on another one dependent mean that its value is going to be related to some other one and this really straightforward example you have B which is equal to a + 10 so B is dependent on a now you can have think that a bit more complex for example um here you have B is equal to a + 10 and then some some condition C is equal B and you want to know is C somehow controllable by the user is see something that the user control or is see something that is not controllable by the user C provide anpi for that and we basically have two function is dependent which is going to take a contract a Target variable a source variable and a context I'm going to go over what is a context in a few and ised which um text uh which TT a Target and a context it's Eed is mostly like a shortcut for is dependent against control variable controlled by the user in the sense that any function parameter message. sender message. dat to understand why there is this notion of context um let's take this example so in this contract we have two variable one and two you have two function direct set which just set variable one to the user input and indirect set which set variable two to variable one if you just look at inir set if you just consider this and you look at okay what are the dependency on this VAR on this function for variable two the only dependency is variable one which is straightforward now if you look at all the dependency across all the function from the contract you you're going to realize that because variable one is dependent on I uh and variable two is dependent on variable one there is a transition happening so variable two is also dependent on I if you consider all the function that can be called in this contract and now if you use that back in the API of slitter what is going to happen is that you can use again like for example the E function to know if a VAR is controlled by the user and you can do it in the context of indirect set or in the context of my contract here if you run this so you will kind of see that varable to is it controlled by the user in the context of just indirect set no because it's not directly controllable however if you do the same in the context of my contract so if you consider all the function yes because the user can call Direct set and can then call indirect set again this is more useful if you start building complex analysis but it can allow you to really kind of uh create create tools and create analysis that are really more kind of precise and in in depth okay any question W the data dependency some of the most advanced detector that we are building are going to use like for example data dependency apart from constant aren't all variable dependent on the user it depend on the context that you are looking at and not necessarily because for example you might have like a a loop a loop V Loop like a sorry variable used to do Loop iteration which is not going to be directly controlled by the user you can also filter out p on only owner so for example some variable are only going to be controlled by the owner and not by of normal user some variable are going to be coming from other contract and not directly controllable by the user there is also like Nuance into what you define as dependent and controllable some variable for example like if you have a counter which is going to be incremented some some you know every time you do some operation this is not going to be easily controllable by the user ver is something where the user can just do an assignments to it okay uh where to start so where where you can start with with all all of that um one website that might help you is secure contract.
com so this is a website where we provide a lot of guidance and a lot of kind of guideline into how to build secure contract we have tutorial for fing and also for for L and program analysis through this website you're going to see some of the API that I've described through this presentation and there are a couple of exercise just to help you kind of get get started with slitter if you clone slitter directly and you go into slitter tools demo there is a default folder with a couple of things and bate Cod that might help you it's going to create kind of like directly like a tool command line with argument passing just to make it easier for you to kind of start playing with it something I would highly recommend is to read uh the detector from slitter because we have a lot of detectors I mentioned and they're going to give you some insight into the API into what's possible into how the API are used is going to give you of a bit more insight into some of the flavor of how to build static analyzer okay um so slitter on a high level is an open source framework to Custom Custom analysis on top of it what I would recommend is just try it out you know like I'm listing here a couple of example of things that you can try to build a b that takes an address and show other the function that don't have only own Earth that can transfer asset this is just going to help you kind of to connect together all the different piece of the IP that we th we saw through this presentation or maybe build a web interface that show the storage layout on a deploy contract again this is just to kind of play a bit with the API um the last example I'm giving here is to build a tool that provide a function and from this function is going to show all the location where it can revert um again just a bit to play with the API and see what you can do if you need help we have a GitHub so GitHub issue or GitHub discussion and we also have a slack more generally block more generally U for any question with our tool or so this presentation and all the rules for the aaton are going to be in github.com critics okay any question I know that was a lot you did it yes this is a highly technical Workshop but um if there's any other I can imagine that there'll be maybe other questions uh once people view also the the workshop uh online will as it's recorded and that could happen so I can imagine some questions there and of course people can come and bug you at your booth yes we yeah that's a good point we will have a booth during the acatan so don't hesitate to to come say hi there are going to be a couple of Trail bits people you know walking around so don't hesitate you have like a big fat t-shirt that people can recognize you and we have a couple of them I don't know how recognizable it's going to be but yeah it's going to be 12 bits on the back so good suit it suit it up so that people know to bug uh and find you in the crowd um so yeah really cool um what else can we say like like I you already mentioned it but of course you're going to put everything in the Discord and so people can find everything and yeah I think I think that's that's it for you is there I'm looking at the chat uh what we won't be following we won't be following trail of bits like crypto Handel and that's really good that's a good one it yeah that's a nice that's very cute what about some snake stuff do you have some Slither some Slither merch I immediately when you started talking about s i was I want to take out my Slytherin you know mug that I have my Harry Potter Slytherin we definitely show have some yeah some little snakes uh on just on the booth you know like some Fates F snakes what is this no this is the Trail of bits uh Booth or is it you know the jungle or the mythology of it would be super fun one of our tool is called Medusa so it's also a good connection nice very nice yeah exactly Hogwarts team confirmed yeah you guys just need to get some magical some little like Harry Potter hats or something um wonderful well thank you so much uh Justin for you know doing this wonderful workshop for participating in the E them boot camp um as mentioned earlier I'm happy to stay online and facilitate some team building or if anybody uh wants to just you know uh I open the stage to to everyone really to get to know each other or if there's any questions or if people are already like thinking of what to build um this is your moment and before before ending I also want to say thanks to to you for the organization um really looking forward for for this event and um yeah meeting everyone yeah it's gonna be fun thank you so much all right are you guys too shy is someone going to take off their no just like I got the info I'm out that's also very fine just keep in mind that tomorrow we have the Oasis uh
Automatic transcript — names and jargon may be misspelled.