โ† All cheat sheets

ROPGADGET-PWNDBG

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Binary exploitation tools for finding ROP gadgets and debugging
with enhanced GDB capabilities.

ROPGADGET#


    

INSTALLATION#

pip install ROPgadget                # PyPI
pip install capstone                 # Required dependency
git clone https://github.com/JonathanSalwan/ROPgadget  # From source

BASIC USAGE#

ROPgadget --binary ./vulnerable                # List all gadgets
ROPgadget --binary ./vulnerable --rawArch=x86  # Specify architecture
ROPgadget --binary ./vulnerable --rawMode=64   # Specify mode

SEARCHING GADGETS#

# Filter by instruction
ROPgadget --binary ./vuln --only "pop|ret"
ROPgadget --binary ./vuln --only "mov|pop|ret"
ROPgadget --binary ./vuln --only "syscall"
ROPgadget --binary ./vuln --only "int"

# Search specific gadgets
ROPgadget --binary ./vuln --filter "pop rdi"
ROPgadget --binary ./vuln --string "/bin/sh"
ROPgadget --binary ./vuln --opcode "c3"        # Search by opcode
ROPgadget --binary ./vuln --memstr "/bin/sh"    # String in memory

# Exclude bad characters
ROPgadget --binary ./vuln --badbytes "0a|0d|00"

# Limit gadget depth
ROPgadget --binary ./vuln --depth 5            # Max instructions

COMMON GADGETS TO FIND#

# 64-bit Linux syscall setup
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rdi"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rsi"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rdx"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rax"
ROPgadget --binary ./vuln | grep "syscall"

# 32-bit Linux syscall setup
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop eax"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop ebx"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop ecx"
ROPgadget --binary ./vuln --only "pop|ret" | grep "pop edx"
ROPgadget --binary ./vuln | grep "int 0x80"

# Stack pivot
ROPgadget --binary ./vuln | grep "xchg.*esp"
ROPgadget --binary ./vuln | grep "leave"

# Write-what-where
ROPgadget --binary ./vuln | grep "mov \[.*\]"
ROPgadget --binary ./vuln | grep "mov qword ptr"

ROPCHAIN GENERATION#

# Auto-generate ROP chain (Linux x86)
ROPgadget --binary ./vuln --ropchain

# Auto-generate for specific architecture
ROPgadget --binary ./vuln --ropchain --rawArch=x86 --rawMode=32

# Output Python-ready format
ROPgadget --binary ./vuln --ropchain --nojop --nosys
# Search in libc
ROPgadget --binary /lib/x86_64-linux-gnu/libc.so.6 --only "pop|ret"

# Multiple binaries
ROPgadget --binary ./vuln --only "pop|ret"
ROPgadget --binary ./libc.so.6 --only "pop|ret"

OUTPUT OPTIONS#

ROPgadget --binary ./vuln --count                # Count gadgets only
ROPgadget --binary ./vuln --offset 0x400000      # Add base offset
ROPgadget --binary ./vuln --range 0x400000-0x401000  # Address range
ROPgadget --binary ./vuln --thumb                # ARM Thumb mode

=========================================================================

PWNDBG#

Enhanced GDB plugin for exploit development and reverse engineering.

INSTALLATION#

git clone https://github.com/pwndbg/pwndbg
cd pwndbg && ./setup.sh            # Auto-installs dependencies

# Alternative: with pip
pip install pwndbg

# Configuration (~/.gdbinit)
# source /path/to/pwndbg/gdbinit.py

STARTING#

gdb ./vulnerable                    # Start with binary
gdb -p PID                          # Attach to process
gdb -q ./vulnerable                 # Quiet mode

CONTEXT DISPLAY#

context                             # Show full context display
set context-sections all            # Show all sections
set context-sections regs disasm code stack backtrace
set context-output /dev/pts/2       # Output to different terminal

BINARY ANALYSIS#

checksec                            # Security features (NX, PIE, etc.)
elfheader                           # ELF header information
elfsections                         # Section addresses and sizes
got                                 # Global Offset Table entries
plt                                 # Procedure Linkage Table entries
entry                               # Entry point address
main                                # Address of main()
canary                              # Show stack canary value
piebase                             # PIE base address

MEMORY EXAMINATION#

vmmap                               # Virtual memory map
vmmap libc                          # Filter by library
vmmap 0x7fff00000000                # Show mapping at address
search -s "/bin/sh"                 # Search string in memory
search -p 0xdeadbeef                # Search pattern (pointer)
search -x "9090"                    # Search hex bytes
search -t byte 0x41                 # Search by type

STACK OPERATIONS#

telescope                           # Smart stack display
telescope $rsp 20                   # Show 20 entries from RSP
telescope 0x7fffffffe000 10         # From specific address
stack 20                            # Alias for telescope $rsp
retaddr                             # Show return addresses on stack

HEAP ANALYSIS#

heap                                # Overview of heap state
bins                                # All bin lists
fastbins                            # Fastbin freelist
unsortedbin                         # Unsorted bin
smallbins                           # Small bins
largebins                           # Large bins
tcachebins                          # Tcache bins (glibc 2.26+)
vis_heap_chunks                     # Visual heap layout
heap -v                             # Verbose heap info
top_chunk                           # Top chunk info
malloc_chunk 0x555555758000         # Inspect specific chunk
try_free 0x555555758010             # Predict what free() will do
find_fake_fast &__malloc_hook       # Find fake fastbin candidates

DISASSEMBLY#

nearpc                              # Disassemble around PC
nearpc 20                           # Show 20 instructions
pdisass                             # Enhanced disassembly
emulate 10                          # Emulate next 10 instructions
u main                              # Disassemble function
nextcall                            # Show next call instruction
nextjmp                             # Show next jump
nextret                             # Show next ret
xinfo 0x400000                      # Info about address

EXPLOIT DEVELOPMENT#

# Cyclic pattern (offset finding)
cyclic 200                          # Generate 200-byte pattern
cyclic -l 0x61616166                # Find offset (lookup)
cyclic -l faaa                      # Find offset (string)
cyclic -n 8 200                     # 64-bit pattern
cyclic -n 8 -l 0x6161616161616166   # 64-bit offset lookup

# ROP gadget search (built-in)
rop                                 # Search common gadgets
rop --grep "pop rdi"                # Filter gadgets

# Format string
fmtarg 0x7fffffffe100               # Find format string offset

REGISTER OPERATIONS#

regs                                # Enhanced register display
set $rdi = 0x41414141               # Set register value
set $rip = 0x400000                 # Set instruction pointer

BREAKPOINTS#

break *0x400500                     # Break at address
break main                         # Break at function
break main+42                      # Break at offset
hbreak *0x400500                    # Hardware breakpoint
dq $rsp                            # Dump qwords at address
dd $rsp                            # Dump dwords
db $rsp                            # Dump bytes

PROCESS CONTROL#

r                                   # Run program
r < input.txt                       # Run with input file
c                                   # Continue
ni                                  # Step over (instruction)
si                                  # Step into (instruction)
finish                              # Run until ret

MEMORY WRITE#

set {int}0x400000 = 0x90909090      # Write dword
set {long}0x400000 = 0x41414141     # Write qword
patch $rsp 0x4141414141414141       # Patch memory
patch $rsp "AAAA"                   # Patch with string

PWNDBG + PWNTOOLS WORKFLOW#

# In Python exploit script:
p = gdb.debug('./vuln', '''
    b *main+42
    c
''')

# Or attach to running process:
p = process('./vuln')
gdb.attach(p, '''
    set follow-fork-mode child
    b *0x400686
    c
''')

# Use pwndbg commands in GDB while pwntools manages I/O

USEFUL PWNDBG SETTINGS#

# In ~/.gdbinit or at runtime
set context-clear-screen on         # Clear screen on stop
set show-flags on                   # Show CPU flags
set resolve-heap-via-heuristic on   # Better heap analysis
set dereference-limit 5             # Pointer chain depth
set context-ghidra always           # Ghidra decompiler view

COMMON WORKFLOW#

1. checksec                         # Identify protections
2. cyclic 200 > pattern.txt         # Generate pattern
3. r < pattern.txt                  # Run with pattern
4. cyclic -l $rsp_value             # Find offset at crash
5. vmmap                            # Find useful regions
6. search -s "/bin/sh"              # Find strings
7. rop --grep "pop rdi"             # Find gadgets
8. got                              # Check GOT for leaks
9. Build exploit in pwntools
10. gdb.attach(p) to debug live

TIPS#

  - pwndbg auto-displays context on every stop (regs, code, stack)
  - Use vis_heap_chunks for visual heap exploitation debugging
  - try_free predicts double-free and corruption issues
  - cyclic in pwndbg matches pwntools cyclic patterns
  - telescope resolves pointer chains automatically
  - Use vmmap to find rwx regions for shellcode
  - checksec output determines your exploit strategy
  - search command works across all mapped memory regions