ROPGADGET-PWNDBG
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Binary exploitation tools for finding ROP gadgets and debugging with enhanced GDB capabilities.
ROPGADGET#
INSTALLATION#
pip install ROPgadget # PyPI pip install capstone # Required dependency git clone https://github.com/JonathanSalwan/ROPgadget # From source
BASIC USAGE#
ROPgadget --binary ./vulnerable # List all gadgets ROPgadget --binary ./vulnerable --rawArch=x86 # Specify architecture ROPgadget --binary ./vulnerable --rawMode=64 # Specify mode
SEARCHING GADGETS#
# Filter by instruction ROPgadget --binary ./vuln --only "pop|ret" ROPgadget --binary ./vuln --only "mov|pop|ret" ROPgadget --binary ./vuln --only "syscall" ROPgadget --binary ./vuln --only "int" # Search specific gadgets ROPgadget --binary ./vuln --filter "pop rdi" ROPgadget --binary ./vuln --string "/bin/sh" ROPgadget --binary ./vuln --opcode "c3" # Search by opcode ROPgadget --binary ./vuln --memstr "/bin/sh" # String in memory # Exclude bad characters ROPgadget --binary ./vuln --badbytes "0a|0d|00" # Limit gadget depth ROPgadget --binary ./vuln --depth 5 # Max instructions
COMMON GADGETS TO FIND#
# 64-bit Linux syscall setup ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rdi" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rsi" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rdx" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop rax" ROPgadget --binary ./vuln | grep "syscall" # 32-bit Linux syscall setup ROPgadget --binary ./vuln --only "pop|ret" | grep "pop eax" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop ebx" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop ecx" ROPgadget --binary ./vuln --only "pop|ret" | grep "pop edx" ROPgadget --binary ./vuln | grep "int 0x80" # Stack pivot ROPgadget --binary ./vuln | grep "xchg.*esp" ROPgadget --binary ./vuln | grep "leave" # Write-what-where ROPgadget --binary ./vuln | grep "mov \[.*\]" ROPgadget --binary ./vuln | grep "mov qword ptr"
ROPCHAIN GENERATION#
# Auto-generate ROP chain (Linux x86) ROPgadget --binary ./vuln --ropchain # Auto-generate for specific architecture ROPgadget --binary ./vuln --ropchain --rawArch=x86 --rawMode=32 # Output Python-ready format ROPgadget --binary ./vuln --ropchain --nojop --nosys
MULTI-BINARY SEARCH#
# Search in libc ROPgadget --binary /lib/x86_64-linux-gnu/libc.so.6 --only "pop|ret" # Multiple binaries ROPgadget --binary ./vuln --only "pop|ret" ROPgadget --binary ./libc.so.6 --only "pop|ret"
OUTPUT OPTIONS#
ROPgadget --binary ./vuln --count # Count gadgets only ROPgadget --binary ./vuln --offset 0x400000 # Add base offset ROPgadget --binary ./vuln --range 0x400000-0x401000 # Address range ROPgadget --binary ./vuln --thumb # ARM Thumb mode =========================================================================
PWNDBG#
Enhanced GDB plugin for exploit development and reverse engineering.
INSTALLATION#
git clone https://github.com/pwndbg/pwndbg cd pwndbg && ./setup.sh # Auto-installs dependencies # Alternative: with pip pip install pwndbg # Configuration (~/.gdbinit) # source /path/to/pwndbg/gdbinit.py
STARTING#
gdb ./vulnerable # Start with binary gdb -p PID # Attach to process gdb -q ./vulnerable # Quiet mode
CONTEXT DISPLAY#
context # Show full context display set context-sections all # Show all sections set context-sections regs disasm code stack backtrace set context-output /dev/pts/2 # Output to different terminal
BINARY ANALYSIS#
checksec # Security features (NX, PIE, etc.) elfheader # ELF header information elfsections # Section addresses and sizes got # Global Offset Table entries plt # Procedure Linkage Table entries entry # Entry point address main # Address of main() canary # Show stack canary value piebase # PIE base address
MEMORY EXAMINATION#
vmmap # Virtual memory map vmmap libc # Filter by library vmmap 0x7fff00000000 # Show mapping at address search -s "/bin/sh" # Search string in memory search -p 0xdeadbeef # Search pattern (pointer) search -x "9090" # Search hex bytes search -t byte 0x41 # Search by type
STACK OPERATIONS#
telescope # Smart stack display telescope $rsp 20 # Show 20 entries from RSP telescope 0x7fffffffe000 10 # From specific address stack 20 # Alias for telescope $rsp retaddr # Show return addresses on stack
HEAP ANALYSIS#
heap # Overview of heap state bins # All bin lists fastbins # Fastbin freelist unsortedbin # Unsorted bin smallbins # Small bins largebins # Large bins tcachebins # Tcache bins (glibc 2.26+) vis_heap_chunks # Visual heap layout heap -v # Verbose heap info top_chunk # Top chunk info malloc_chunk 0x555555758000 # Inspect specific chunk try_free 0x555555758010 # Predict what free() will do find_fake_fast &__malloc_hook # Find fake fastbin candidates
DISASSEMBLY#
nearpc # Disassemble around PC nearpc 20 # Show 20 instructions pdisass # Enhanced disassembly emulate 10 # Emulate next 10 instructions u main # Disassemble function nextcall # Show next call instruction nextjmp # Show next jump nextret # Show next ret xinfo 0x400000 # Info about address
EXPLOIT DEVELOPMENT#
# Cyclic pattern (offset finding) cyclic 200 # Generate 200-byte pattern cyclic -l 0x61616166 # Find offset (lookup) cyclic -l faaa # Find offset (string) cyclic -n 8 200 # 64-bit pattern cyclic -n 8 -l 0x6161616161616166 # 64-bit offset lookup # ROP gadget search (built-in) rop # Search common gadgets rop --grep "pop rdi" # Filter gadgets # Format string fmtarg 0x7fffffffe100 # Find format string offset
REGISTER OPERATIONS#
regs # Enhanced register display set $rdi = 0x41414141 # Set register value set $rip = 0x400000 # Set instruction pointer
BREAKPOINTS#
break *0x400500 # Break at address break main # Break at function break main+42 # Break at offset hbreak *0x400500 # Hardware breakpoint dq $rsp # Dump qwords at address dd $rsp # Dump dwords db $rsp # Dump bytes
PROCESS CONTROL#
r # Run program r < input.txt # Run with input file c # Continue ni # Step over (instruction) si # Step into (instruction) finish # Run until ret
MEMORY WRITE#
set {int}0x400000 = 0x90909090 # Write dword
set {long}0x400000 = 0x41414141 # Write qword
patch $rsp 0x4141414141414141 # Patch memory
patch $rsp "AAAA" # Patch with string
PWNDBG + PWNTOOLS WORKFLOW#
# In Python exploit script:
p = gdb.debug('./vuln', '''
b *main+42
c
''')
# Or attach to running process:
p = process('./vuln')
gdb.attach(p, '''
set follow-fork-mode child
b *0x400686
c
''')
# Use pwndbg commands in GDB while pwntools manages I/O
USEFUL PWNDBG SETTINGS#
# In ~/.gdbinit or at runtime set context-clear-screen on # Clear screen on stop set show-flags on # Show CPU flags set resolve-heap-via-heuristic on # Better heap analysis set dereference-limit 5 # Pointer chain depth set context-ghidra always # Ghidra decompiler view
COMMON WORKFLOW#
1. checksec # Identify protections 2. cyclic 200 > pattern.txt # Generate pattern 3. r < pattern.txt # Run with pattern 4. cyclic -l $rsp_value # Find offset at crash 5. vmmap # Find useful regions 6. search -s "/bin/sh" # Find strings 7. rop --grep "pop rdi" # Find gadgets 8. got # Check GOT for leaks 9. Build exploit in pwntools 10. gdb.attach(p) to debug live
TIPS#
- pwndbg auto-displays context on every stop (regs, code, stack) - Use vis_heap_chunks for visual heap exploitation debugging - try_free predicts double-free and corruption issues - cyclic in pwndbg matches pwntools cyclic patterns - telescope resolves pointer chains automatically - Use vmmap to find rwx regions for shellcode - checksec output determines your exploit strategy - search command works across all mapped memory regions