Skip to main content
Sometimes you know exactly where a useful gadget is located, or you want to analyze specific addresses without doing a full gadget search. angrop provides methods to analyze individual addresses and work with custom gadget lists.

Analyzing Specific Addresses

analyze_gadget() - Single Gadget

Analyze a specific address and filter out conditional branches:
Key behavior:
  • Filters out gadgets with conditional branches
  • Returns a single RopGadget object or None
  • Automatically adds the gadget to the ROP chain builder
  • Re-screens all gadgets based on current badbytes

analyze_addr() - Multiple Gadgets with Branches

For addresses with conditional branches, get all possible execution paths:
Key behavior:
  • Includes gadgets with conditional branches
  • Returns a list of gadgets (different execution paths)
  • Useful for analyzing complex gadgets with multiple outcomes

Source Code Reference

From angrop/rop.py:104-128:

Analyzing Custom Gadget Lists

analyze_gadget_list() - Batch Analysis

If you have a list of addresses from another tool (like ROPgadget or ropper), analyze them all:
From angrop/rop.py:130-145:

Practical Examples

Example 1: Verifying Manual Gadgets

Example 2: Analyzing After Info Leak

Example 3: Combining Full Search with Custom Gadgets

Understanding Gadget Screening

When you call analyze_gadget() or analyze_addr(), angrop automatically:
  1. Analyzes the address using symbolic execution
  2. Adds to internal list (self._all_gadgets)
  3. Re-screens all gadgets based on:
    • Current badbytes
    • Gadget type (ROP, syscall, pivot)
  4. Updates public lists:
    • rop.rop_gadgets
    • rop.syscall_gadgets
    • rop.pivot_gadgets
  5. Bootstraps chain builder to use new gadgets

Handling Badbytes

If a gadget address contains badbytes, angrop tries to find equivalent gadgets:
From the source (angrop/rop.py:78-91):

Gadget Properties

Once you have a gadget, you can inspect its properties:

When to Use Each Method

Performance Tips

  1. Use multiprocessing for large address lists
  2. Disable optimization initially with optimize=False if you’re still exploring
  3. Cache gadgets with save_gadgets() and load_gadgets()
  4. Set badbytes early to avoid analyzing unusable gadgets