Skip to main content
The ROP class is angrop’s primary interface for semantic-aware ROP gadget discovery and chain building. It extends angr’s Analysis class and provides methods for finding gadgets, managing them, and building exploit chains.

Class Definition

Semantic-aware ROP gadget finder that analyzes binary code to discover exploitable gadgets and build ROP chains.

Constructor

bool
default:"True"
If true, skip blocks that are not near ret instructions. This significantly speeds up gadget finding.
int | None
default:"None"
Limits the size of blocks considered. Longer blocks are less likely to be good ROP gadgets.
int | None
default:"None"
Maximum number of symbolic memory accesses to allow in a gadget.
bool | None
default:"None"
When True, skip gadgets with conditional branches, floating point operations, and jumps. Allows smaller gadget size. If None, automatically decides based on binary size.
any
default:"None"
Deprecated. This parameter is no longer used in angrop.
bool
default:"False"
Execute ROP chain in ARM Thumb mode. Only affects ARM architecture. angrop does not switch modes within a chain.
bool
default:"False"
Find kernel mode gadgets instead of user mode gadgets.
int
default:"80"
Maximum allowable stack change for gadgets. Max stack_change = stack_gsize * arch.bytes.
bool
default:"False"
Whether to support conditional branches. This option significantly impacts gadget finding speed.
int
default:"2"
Maximum basic block count to consider in gadgets.

Attributes

After calling find_gadgets(), find_gadgets_single_threaded(), or load_gadgets(), the following attributes are populated:
list[RopGadget]
List of gadgets used for ROP operations (e.g., pop rax; ret).
list[PivotGadget]
List of gadgets used for stack pivoting (e.g., mov rsp, rbp; ret).
list[SyscallGadget]
List of gadgets used for invoking system calls (e.g., syscall; ret or int 0x80; ret).
list[int]
List of bytes that should not appear in generated ROP chains.
int | None
Integer value used when popping useless registers. If None, symbolic values are used.
RopArch
Architecture object from the gadget finder.

Gadget Discovery Methods

find_gadgets

Finds all gadgets in the binary using multiple processes.
bool
default:"True"
Whether to run chain_builder.optimize(). This may take time but makes the chain builder more powerful.
int
default:"4"
Number of processes to use for parallel gadget analysis.
bool
default:"True"
Whether to display a progress bar during gadget finding.
Returns: List of discovered ROP gadgets.

find_gadgets_single_threaded

Finds all gadgets in the binary using a single thread. Useful for debugging or when multiprocessing causes issues.
bool
default:"True"
Whether to display a progress bar.
bool
default:"True"
Whether to run chain_builder.optimize().
Returns: List of discovered ROP gadgets.

analyze_gadget

Analyzes a specific address to identify if it’s a valid ROP gadget. Filters out gadgets containing conditional branches.
int
required
Address to analyze.
Returns: RopGadget object if valid, None otherwise.

analyze_addr

Analyzes an address and returns all possible gadgets starting from that address. This includes gadgets with conditional branches.
int
required
Address to analyze.
Returns: List of RopGadget objects or None.

analyze_gadget_list

Analyzes a list of addresses to identify ROP gadgets.
list[int]
required
List of addresses to analyze.
int
default:"4"
Number of processes to use.
bool
default:"True"
Whether to show progress bar.
bool
default:"True"
Whether to optimize the chain builder.
Returns: List of discovered ROP gadgets.

Gadget Management Methods

save_gadgets

Saves discovered gadgets to a file using pickle serialization.
str
required
Path to the file where gadgets will be stored.

load_gadgets

Loads gadgets from a previously saved file.
str
required
Path to the file containing saved gadgets.
bool
default:"True"
Whether to optimize the chain builder after loading.

Configuration Methods

set_badbytes

Define bytes that should not appear in the generated ROP chain.
list[int]
required
List of 8-bit integers representing bad bytes (e.g., [0x00, 0x09] for null and tab).

get_badbytes

Returns: List of currently configured bad bytes.

set_roparg_filler

Define the filler value used when ROP chains need to pop useless registers.
int | None
required
Integer value to use as filler, or None to use symbolic values (constraint solver will choose, usually 0).

Chain Building Methods

All public methods from ChainBuilder are automatically exposed through the ROP instance after gadgets are found. These include:
  • set_regs() - Set register values
  • move_regs() - Move values between registers
  • write_to_mem() - Write data to memory
  • func_call() - Call a function with arguments
  • do_syscall() - Invoke a system call
  • execve() - Execute execve syscall
  • pivot() - Perform stack pivot
  • And more…
See the ChainBuilder documentation for details.

Example Usage

Internal Properties

ChainBuilder
Property that returns the ChainBuilder instance. Created lazily on first access. All ChainBuilder public methods are copied to the ROP instance.