ChainBuilder class provides high-level methods to generate common ROP chains based on discovered gadgets. It handles register setting, memory operations, function calls, system calls, and more.
Class Definition
Constructor
angr.Project
required
The angr project instance.
list[RopGadget]
required
List of ROP gadgets to use for chain building.
list[PivotGadget]
required
List of stack pivot gadgets.
list[SyscallGadget]
required
List of syscall gadgets.
RopArch
required
Architecture object describing the target platform.
list[int]
required
List of bytes to avoid in the generated chains.
int | None
required
Integer used when popping superfluous registers, or None for symbolic values.
You typically don’t instantiate ChainBuilder directly. Instead, access it through the ROP class, which automatically exposes all ChainBuilder methods.
Register Operations
set_regs
set[str] | None
Set of register names to preserve (e.g.,
{'eax', 'ebx'}).int | RopValue
Register names mapped to their desired values.
move_regs
set[str] | None
Set of register names to preserve.
str
Mapping where key is destination register and value is source register name.
Memory Operations
write_to_mem
int | RopValue
required
Address where data should be written.
bytes
required
Data to write to memory.
bytes
default:"b'\\xff'"
Byte used to fill/pad the data if necessary.
add_to_mem
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to add to the memory location.
int | None
Size of the data in bits (defaults to architecture word size).
[addr] += value.
Example:
mem_xor
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to XOR with.
int | None
Size of the operation in bytes.
[addr] ^= value.
mem_add
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to add.
int | None
Size of the operation in bytes.
[addr] += value.
mem_or
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to OR with.
int | None
Size of the operation in bytes.
[addr] |= value.
mem_and
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to AND with.
int | None
Size of the operation in bytes.
[addr] &= value.
Function and System Calls
func_call
int | str
required
Address or name of the function to call.
list | tuple
required
List or tuple of arguments to pass to the function.
set[str] | None
Set of registers to preserve.
bool
default:"True"
Whether to continue the ROP chain after invoking the function.
do_syscall
int
required
The syscall number to execute.
list
required
List of register values to set before making the syscall.
bool
default:"True"
Whether to continue the ROP chain after the syscall.
set[str] | None
Set of registers to preserve.
execve
bytes | None
Path of binary to execute. Defaults to
b"/bin/sh\x00".int | None
Address where the path string should be stored.
sigreturn
int | None
Override syscall number if needed.
int
Register values to set in the sigreturn frame.
sigreturn_syscall
int
required
Syscall number for sigreturn.
list
required
Syscall arguments for sigreturn.
int | None
Address to jump to after sigreturn.
Stack Operations
pivot
int | RopValue
required
New stack pointer value or register containing it.
shift
int
required
Number of bytes to shift the stack pointer.
set[str] | None
Set of registers to preserve.
int
default:"-1"
Index of the next PC value.
retsled
int
required
Size of the retsled chain in bytes.
set[str] | None
Set of registers to preserve.
Configuration Methods
set_badbytes
list[int]
required
List of 8-bit integers.
set_roparg_filler
int | None
required
Filler value or None.
optimize
int
default:"1"
Number of processes to use for optimization.
Internal Methods
bootstrap
check_can_do_write
_can_do_write flag.