ROP class is angrop’s primary interface for semantic-aware ROP gadget discovery and chain building. It extends angr’s Analysis class and provides methods for finding gadgets, managing them, and building exploit chains.
Class Definition
Constructor
bool
default:"True"
If true, skip blocks that are not near ret instructions. This significantly speeds up gadget finding.
int | None
default:"None"
Limits the size of blocks considered. Longer blocks are less likely to be good ROP gadgets.
int | None
default:"None"
Maximum number of symbolic memory accesses to allow in a gadget.
bool | None
default:"None"
When True, skip gadgets with conditional branches, floating point operations, and jumps. Allows smaller gadget size. If None, automatically decides based on binary size.
any
default:"None"
Deprecated. This parameter is no longer used in angrop.
bool
default:"False"
Execute ROP chain in ARM Thumb mode. Only affects ARM architecture. angrop does not switch modes within a chain.
bool
default:"False"
Find kernel mode gadgets instead of user mode gadgets.
int
default:"80"
Maximum allowable stack change for gadgets. Max stack_change = stack_gsize * arch.bytes.
bool
default:"False"
Whether to support conditional branches. This option significantly impacts gadget finding speed.
int
default:"2"
Maximum basic block count to consider in gadgets.
Attributes
After callingfind_gadgets(), find_gadgets_single_threaded(), or load_gadgets(), the following attributes are populated:
list[RopGadget]
List of gadgets used for ROP operations (e.g.,
pop rax; ret).list[PivotGadget]
List of gadgets used for stack pivoting (e.g.,
mov rsp, rbp; ret).list[SyscallGadget]
List of gadgets used for invoking system calls (e.g.,
syscall; ret or int 0x80; ret).list[int]
List of bytes that should not appear in generated ROP chains.
int | None
Integer value used when popping useless registers. If None, symbolic values are used.
RopArch
Architecture object from the gadget finder.
Gadget Discovery Methods
find_gadgets
bool
default:"True"
Whether to run chain_builder.optimize(). This may take time but makes the chain builder more powerful.
int
default:"4"
Number of processes to use for parallel gadget analysis.
bool
default:"True"
Whether to display a progress bar during gadget finding.
find_gadgets_single_threaded
bool
default:"True"
Whether to display a progress bar.
bool
default:"True"
Whether to run chain_builder.optimize().
analyze_gadget
int
required
Address to analyze.
analyze_addr
int
required
Address to analyze.
analyze_gadget_list
list[int]
required
List of addresses to analyze.
int
default:"4"
Number of processes to use.
bool
default:"True"
Whether to show progress bar.
bool
default:"True"
Whether to optimize the chain builder.
Gadget Management Methods
save_gadgets
str
required
Path to the file where gadgets will be stored.
load_gadgets
str
required
Path to the file containing saved gadgets.
bool
default:"True"
Whether to optimize the chain builder after loading.
Configuration Methods
set_badbytes
list[int]
required
List of 8-bit integers representing bad bytes (e.g.,
[0x00, 0x09] for null and tab).get_badbytes
set_roparg_filler
int | None
required
Integer value to use as filler, or None to use symbolic values (constraint solver will choose, usually 0).
Chain Building Methods
All public methods from ChainBuilder are automatically exposed through the ROP instance after gadgets are found. These include:set_regs()- Set register valuesmove_regs()- Move values between registerswrite_to_mem()- Write data to memoryfunc_call()- Call a function with argumentsdo_syscall()- Invoke a system callexecve()- Execute execve syscallpivot()- Perform stack pivot- And more…
Example Usage
Internal Properties
ChainBuilder
Property that returns the ChainBuilder instance. Created lazily on first access. All ChainBuilder public methods are copied to the ROP instance.