Cwe Checker

cwe_checker finds vulnerable patterns in binary executables

Cybersecurity & Ethical HackingRustLGPL-3.0

Abstract

Cwe Checker is an open-source Cybersecurity & Ethical Hacking project. Cwe_checker finds vulnerable patterns in binary executables. cwe_checker is a suite of checks to detect common bug classes such as Null pointer dereferences and buffer overflows. These bug classes are formally known as Common Weakness Enumerations (CWEs). It is built using Rust. The complete source code is publicly available on GitHub under the GNU Lesser General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

cwe_checker is a suite of checks to detect common bug classes such as Null pointer dereferences and buffer overflows. These bug classes are formally known as Common Weakness Enumerations (CWEs). The checks are based on a variety of anaylsis techniques ranging from simple heuristics to abstract interpretation-based data-flow analysis. Its main goal is to aid analysts to quickly find potentially vulnerable code paths.

Its main focus are ELF binaries that are commonly found on Linux and Unix operating systems. The cwe_checker uses Ghidra to disassemble binaries into one common intermediate representation and implements its own analyses on this IR. Hence, the analyses can be run on most CPU architectures that Ghidra can disassemble, which makes the cwe_checker a valuable tool for firmware analysis.

2. Objective

cwe_checker finds vulnerable patterns in binary executables

This project demonstrates how Rust can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Rust

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Rust toolchain (rustup / cargo)
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/fkie-cad/cwe_checker.git
cd cwe_checker
  1. Rust >= 1.82
  2. Ghidra >= 10.2
docker run --rm -v /PATH/TO/BINARY:/input ghcr.io/fkie-cad/cwe_checker /input
cwe_checker BINARY
nix run github:fkie-cad/cwe_checker -- BINARY

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by fkie-cad and published on GitHub under the GNU Lesser General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship