Skip to main content

Overview

This example shows how to build a ROP chain that executes /bin/sh using the execve() system call. This is one of the most common goals in exploit development.

CLI Approach

The easiest way to generate an execve chain is using the command-line tool:

CLI Output Example

This chain:
  1. Sets up the necessary registers
  2. Prepares arguments for execve()
  3. Calls execve@plt with appropriate arguments

Python API Approach

1

Initialize angrop

2

Find and optimize gadgets

3

Build execve chain

There are two approaches depending on whether the binary has an execve function:Method 1: Using execve@plt (if available)
Method 2: Using syscall (if no execve function)
4

Generate payload

Complete Example

Simple execve() Chain

Advanced execve() Chain with Memory Write

How It Works

An execve("/bin/sh", NULL, NULL) chain needs to:
  1. Place “/bin/sh” in memory - Either find it in the binary or write it to a writable location
  2. Set up arguments - Set registers/stack for:
    • arg1: Pointer to “/bin/sh”
    • arg2: NULL (argv)
    • arg3: NULL (envp)
  3. Call execve - Either through PLT, direct symbol, or syscall

CLI Options

The CLI supports additional options:

Understanding the Output

The generated chain uses code_base + offset format:
  • code_base = 0x0: Assumes PIE base is 0 (adjust in your exploit)
  • Each p64() is either a gadget address or data
  • Comments show what each gadget does
In your exploit, you’ll need to adjust code_base if the binary uses PIE/ASLR.