{"id":43705914,"url":"https://github.com/LamentXU123/Typhon","last_synced_at":"2026-02-16T16:00:37.116Z","repository":{"id":312527968,"uuid":"1042629962","full_name":"LamentXU123/Typhon","owner":"LamentXU123","description":"pyjail (python jail) 绕过 一把梭 CTF 工具","archived":false,"fork":false,"pushed_at":"2025-12-14T05:17:16.000Z","size":103318,"stargazers_count":290,"open_issues_count":2,"forks_count":22,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-12-14T21:25:10.207Z","etag":null,"topics":["bypass","ctf","ctf-tools","pyjail","sandbox"],"latest_commit_sha":null,"homepage":"https://typhon.lamentxu.top","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/LamentXU123.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":"COPYRIGHT","agents":null,"dco":null,"cla":null}},"created_at":"2025-08-22T10:15:20.000Z","updated_at":"2025-12-14T05:17:20.000Z","dependencies_parsed_at":"2025-08-31T10:17:21.440Z","dependency_job_id":"ad3bc6d7-d2f6-400f-98ce-36caef318a22","html_url":"https://github.com/LamentXU123/Typhon","commit_stats":null,"previous_names":["team-intn18-soybeanseclab/typhon","lamentxu123/typhon"],"tags_count":13,"template":false,"template_full_name":null,"purl":"pkg:github/LamentXU123/Typhon","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LamentXU123%2FTyphon","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LamentXU123%2FTyphon/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LamentXU123%2FTyphon/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LamentXU123%2FTyphon/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/LamentXU123","download_url":"https://codeload.github.com/LamentXU123/Typhon/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LamentXU123%2FTyphon/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29512225,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-16T09:05:14.864Z","status":"ssl_error","status_checked_at":"2026-02-16T08:55:59.364Z","response_time":115,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bypass","ctf","ctf-tools","pyjail","sandbox"],"created_at":"2026-02-05T06:00:17.292Z","updated_at":"2026-02-16T16:00:37.110Z","avatar_url":"https://github.com/LamentXU123.png","language":"Python","funding_links":[],"categories":["CTF相关"],"sub_categories":[],"readme":"# Typhon: Lets solve pyjail without brain  \n\n[![PyPI Downloads](https://static.pepy.tech/personalized-badge/typhonbreaker?period=total\u0026units=ABBREVIATION\u0026left_color=BLACK\u0026right_color=GREEN\u0026left_text=total%20downloads)](https://pepy.tech/projects/typhonbreaker)\n![License](https://img.shields.io/badge/license-Apache_2.0-cyan.svg)\n![Python_version](https://img.shields.io/pypi/pyversions/TyphonBreaker.svg?logo=python\u0026logoColor=FBE072)\n![PyPI Version](https://img.shields.io/pypi/v/TyphonBreaker)\n![Tests](https://github.com/Team-intN18-SoybeanSeclab/Typhon/actions/workflows/test.yml/badge.svg)\n[![codecov](https://codecov.io/gh/LamentXU123/Typhon/graph/badge.svg?token=JCH6XBAORY)](https://codecov.io/gh/LamentXU123/Typhon)\n\n听着，我已经受够那些愚蠢的CTF pyjail题目了——每次我都要浪费时间在又臭又长的黑名单和各种pyjail总结之间找哪个链子没被过滤，或者在命名空间里一个一个运行`dir()`去找能用的东西。这简直就是一种折磨。\n\n所以这就是Typhon（提丰），一个致力于让你不需要脑子也能做pyjail的一把梭工具。\n\n![image](./image/usage_example.gif)\n\n文档: https://typhon.lamentxu.top/  \n博客: https://www.cnblogs.com/LAMENTXU/articles/19101758\n\n**请务必看完本readme后再使用Typhon工具，尤其是[Q\u0026A](#QA)部分。**\n\n- [Highlights](#Highlights)  \n- [How to Use](#How-to-Use)  \n- [Q\u0026A](#QA)\n- [Proof of Concept](#Proof-of-Concept)  \n- [Limitations](#Limitations)  \n- [Milestones](#Milestones)  \n- [Contributing](#Contributing)  \n- [Credits](#Credits)  \n- [License](#License)  \n\n## Highlights\n\n- 完全开源，免费的一把梭工具  \n- 不需要大脑就能完成pyjail题目，爱护您的脑细胞和眼球\n- 拥有数百条gadgets和几乎所有主流的bypass方法\n- 支持多种函数以达成不同功能，如RCE用`bypassRCE()`, 读文件用`bypassRead()`等等\n- 不依赖任何第三方库，使用纯python3实现\n\n## How to Use\n\n### Install\n\n你可以使用pip进行安装：\n\n```\npip install TyphonBreaker\n```\n\n### Interface\n\n提供 `bypass*` 系列接口。主要见 [API 文档](https://typhon.lamentxu.top/zh-cn/latest/USAGE.html)\n\n## Step by Step Tutorial\n\n你可以通过[示例文档](https://typhon.lamentxu.top/zh-cn/latest/EXAMPLE.html)中的例题来学习 Typhon 的实战用法。以下仅仅提供一个示例。\n\n假设有如下题目：\n\n```python\nimport re\ndef safe_run(cmd):\n    if len(cmd) \u003e 160:\n        return \"Command too long\"\n    if any([i for i in ['import', '__builtins__', '{}'] if i in cmd]):\n        return \"WAF!\"\n    if re.match(r'.*import.*', cmd):\n        return \"WAF!\"\n    exec(cmd, {'__builtins__': {}})\n\nsafe_run(input(\"Enter command: \"))\n```\n\n**Step1. 分析waf**\n\n首先，我们需要分析一下pyjail waf的功能（这可能是唯一需要大脑的地方）。\n\n可以看出，上述题目的waf如下：\n\n- 限制长度最大值为160\n- 在exec的命名空间里没有`__builtins__`\n- 禁止使用`builtins`, `import`, `{}`字符\n- 设置了正则表达式`'.*import.*'`限制条件\n\n**Step2. 将waf导入Typhon**\n\n首先我们将exec行删除：\n\n```python\nimport re\ndef safe_run(cmd):\n    if len(cmd) \u003e 160:\n        return \"Command too long\"\n    if any([i for i in ['import', '__builtins__', '{}'] if i in cmd]):\n        return \"WAF!\"\n    if re.match(r'.*import.*', cmd):\n        return \"WAF!\"\n\nsafe_run(input(\"Enter command: \"))\n```\n\n然后，我们以Typhon对应的bypass函数替代exec行，在对应位置导入WAF, **并在该行上方`import Typhon`**：\n\n```python\nimport re\ndef safe_run(cmd):\n    import Typhon\n    Typhon.bypassRCE(cmd,\n    banned_chr=['__builtins__', 'import', '{}'],\n    banned_re='.*import.*',\n    local_scope={'__builtins__': {}},\n    max_length=160)\n\nsafe_run(input(\"Enter command: \"))\n```\n\n**Step3. 运行**\n\n运行你的题目程序，等待**Jail broken**的信息出现即可。\n\n![image](./image/step-by-step-tutorial.png)\n\n# Q\u0026A\n\n- 何时`import Typhon`？\n\n一定要将行`import Typhon`放在`Typhon`内置绕过函数的上一行（即使你患有PEP-8强迫症）。否则，`Typhon`将无法通过栈帧获取当前的全局变量空间。\n\n**Do:**\n```python\ndef safe_run(cmd):\n    import Typhon\n    Typhon.bypassRCE(cmd,\n    banned_chr=['builtins', 'os', 'exec', 'import'])\n\nsafe_run('cat /f*')\n```\n\n**Don't:**\n```python\nimport Typhon\n\ndef safe_run(cmd):\n    Typhon.bypassRCE(cmd,\n    banned_chr=['builtins', 'os', 'exec', 'import'])\n\nsafe_run('cat /f*')\n```\n\n- 为什么需要使用与题目相同的python版本？\n\nPyjail中存在一些通过索引寻找对应object的gadgets（如继承链）。继承链的利用随着索引变化很大。因此，请务必确保Typhon的运行环境与题目相同。\n\n**无法保证？**\n\n是的，大多数题目都不会给出对应的python版本。因此，**Typhon会在使用涉及版本的gadgets时做出提示**。  \n\n![image](./image/reminder_example.png)\n\n这种情况下往往需要CTF选手自己去找题目环境中该gadgets需要的索引值。  \n\n- 如果题目的`exec`和`eval`没有限制命名空间怎么办？\n\n假设题目没有限制命名空间，则不必填写`local_scope`参数。Typhon会自动使用`import Typhon`时的当前命名空间进行绕过\n\n- 这个payload我用不了能不能换一个？\n\n你可以在参数中加上`print_all_payload=True`，Typhon就会打印其生成的所有payload。\n\n- 这个WEB题好像没开放stdin，我`exec(input())`没用怎么办？\n\n你可以在参数中加上`interactive=False`，Typhon就会禁止使用所有涉及`stdin`的payload。\n\n- 最后输出的payload没回显怎么办？\n\n对于`bypassRCE`，我们认为：**只要命令得到了执行，就是RCE成功。** 至于回显问题，你可以选择反弹shell，时间盲注，或者：添加`print_all_payload=True`参数，查看所有payload，其中可能含有能够成功回显的payload。\n\n## Proof of Concept\n\nTyphon的工作原理如下：\n\n### bypass by path \u0026 technique\n\n我们定义两种bypass方式：\n\n- path: 通过不同的载荷进行绕过（例如`os.system('calc')`和`subprocess.Popen('calc')`）  \n- technique: 使用不同技术对相同的有效载荷进行处理从而绕过（例如，`os.system('c'+'a'+'l'+'c')` 和 `os.system('clac'[::-1])`)  \n\nTyphon内置了上百种path。每次我们要绕过获取某个东西时，我们先通过local_scope找到所有可以用的`path`，接下来，通过`bypasser.py`中的`technique`生成每个`path`对应的不同变体，并尝试绕过黑名单。\n\n### gadgets chain\n\n本思路受到[pyjailbreaker](https://github.com/jailctf/pyjailbreaker)工具的启发。\n\npyjailbreaker不直接通过gadgets一步到位实现RCE，而是一步一步寻找RCE链条中需要的项。如假设存在下列黑名单：\n\n- 本地命名空间无`__builtins__`\n- 禁止使用`builtins`字符\n\n对于这个WAF，Typhon是这样处理的：\n\n- 首先，我们通过`'J'.__class__.__class__`获取`type`\n- 随后，我们找到获取type后可能可以获取builtins的RCE链子`TYPE.__subclasses__(TYPE)[0].register.__globals__['__builtins__']`\n- 已知题目黑名单过滤了`__builtins__`字符，则我们将此path投入bypasser产生数十种变体。选择其中最短的变体：`TYPE.__subclasses__(TYPE)[0].register.__globals__['__snitliub__'[::-1]]`\n- 随后，我们找到获取``__builtins__``后的RCE链子`BUILTINS_SET['breakpoint']()`\n- 最后，我们将代表builtins字典的占位符`BUILTINS_SET`替换为上步中获取的`__builtins__`路径，以此类推，将`TYPE`占位符替换为真实的路径，就得到了最终的payload。\n\n```python\n'J'.__class__.__class__.__subclasses__('J'.__class__.__class__)[0].register.__globals__['__snitliub__'[::-1]]['breakpoint']()\n```\n\n### Step by Step\n\nTyphon的workflow顺序如下：\n\n- 每一个终点函数（`bypassRCE`, `bypassREAD`，etc.）都会调用主函数`bypassMAIN`，主函数会尽可能搜集所有的可用gadgets（如上例中的`type`）并将收集到的内容传递给对应的下级函数。\n- `bypassMAIN`函数在简单分析完当前的变量空间后，会：\n  - 尝试直接RCE（如`help()`, `breakporint()`）\n  - 尝试获取生成器\n  - 尝试获取type\n  - 尝试获取object\n  - 尝试获取bytes\n  - 如当前空间中的``__builtins__``未被删除，但被修改，尝试恢复（如`id.__self__`）\n  - 如当前空间中的``__builtins__``被删除，尝试从其他命名空间恢复\n  - 承上，尝试继承链绕过\n  - 尝试获取import包的能力\n  - 尝试直接通过可能恢复的``__builtins__`` RCE\n  - 将结果传递给下级函数\n- 下级函数拿到`bypassMAIN`的结果后，会根据该函数所实现的需求，选择对应的gadgets进行处理（如`bypassRCE`专注于RCE，`bypassREAD`专注于文件读取，`bypassENV`专注于读取环境变量）。其过程与上述相似。\n\n## Limitations\n\n- 目前Typhon只支持python 3.9及以上版本。\n- 目前Typhon只支持linux沙箱。\n- 目前Typhon尚无法绕过audithook沙箱。\n- 由于Typhon采用局部最优的递归策略，对于一些简单的题目，反而需要耗时更久（约1min）。\n- 目前已知的不支持的bypass方法：\n\n  - Typhon不支持以`list.pop(0)`代替`list[0]`，这是因为Typhon所生成的payload都需要经过本地执行验证才能成立，而`pop`方法在验证时会将元素从列表中删除，从而破坏后续环境。\n\n## Milestones\n\n### v1.0 （已发布）\n\n- [x] 实现基本框架\n\n### v1.1\n\n- [ ] 实现更多绕过器\n    - [x] 使用魔术方法替换二元运算符 (`a.__add__(b)`替换`a+b`)\n    - [ ] `list.pop(0)`替换`list[0]`\n    - [x] `list(dict(a=1))[0]`替换`'a'`\n    - [x] `str()`替换空字符串\n- [ ] 实现内置的bash bypasser \n- [ ] 更好的`bypassREAD`函数  \n- [x] 实现白名单功能\n- [x] 自动寻找`bytes`\n\n### v1.2\n\n- [ ] 实现`audithook`沙箱的绕过  \n- [ ] 在没有长度限制的情况下，不使用局部长度最优的递归算法\n- [ ] 实现`bypassENV`函数，用于环境变量的读取\n\n## Contributing\n\n### 提供Typhon无法解出的题目\n\n我们将长期收集Typhon无法解出的题目。这对提升工具性能及其重要！如果你碰到无法一把梭的题目，请于本仓库打开issue，并写明题目来源（最好有对应的题解），我们会尽可能实现对该题目的自动求解。\n\n作为回报，我们会在下一个release版本中囊括您的github ID。\n\n## Credits\n\n**Author \u0026 Maintainer**\n\n@ [LamentXU (Weilin Du)](https://github.com/LamentXU123)  \n\n**Contributors**\n\n感谢所有对此项目做过贡献的人：\n\n\u003ca href=\"https://github.com/eryajf/learn-github/graphs/contributors\"\u003e\n  \u003cimg src=\"https://contrib.rocks/image?repo=Team-intN18-SoybeanSeclab/Typhon\" /\u003e\n\u003c/a\u003e\n\n**Copyright**\n\n针对bash绕过的内置绕过器，感谢[bashFuck](https://github.com/ProbiusOfficial/bashFuck)项目的作者@ [ProbiusOfficial](https://github.com/ProbiusOfficial)，其[License](https://github.com/ProbiusOfficial/bashFuck/blob/main/README.md)于此。\n\nCopyright (c) 2024 ProbiusOfficial.\n\n下游项目（若有）请务必涵盖此。\n\n另：当前版本中尚未添加此功能。此copyright信息为预先保留。\n\n**Speical Thanks**\n\n@ [黄豆安全实验室](https://hdsec.cn)给予我必须的鼓励  \n@ [pyjailbreaker](https://github.com/jailctf/pyjailbreaker)项目给予我启发  \n\n## License\n\n这个项目在[Apache 2.0](https://github.com/LamentXU123/Typhon/blob/main/LICENSE)协议下发布。\n\nCopyright (c) 2025 Weilin Du.\n\n## 404星链计划\n\u003cimg src=\"https://github.com/knownsec/404StarLink/raw/master/Images/logo.png\" width=\"30%\"\u003e\n\nTyphon 现已加入 [404星链计划](https://github.com/knownsec/404StarLink)\n\n\u003cpicture\u003e\n  \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://api.star-history.com/svg?repos=Team-intN18-SoybeanSeclab/Typhon\u0026type=Date\u0026theme=dark\" /\u003e\n  \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://api.star-history.com/svg?repos=Team-intN18-SoybeanSeclab/Typhon\u0026type=Date\" /\u003e\n  \u003cimg alt=\"Star History Chart\" src=\"https://api.star-history.com/svg?repos=Team-intN18-SoybeanSeclab/Typhon\u0026type=Date\" /\u003e\n\u003c/picture\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLamentXU123%2FTyphon","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FLamentXU123%2FTyphon","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLamentXU123%2FTyphon/lists"}