Skip to main content

Overview

Register control is fundamental to ROP chain construction. angrop provides powerful primitives for setting and moving register values, which can be combined to create complex chains.

Setting Registers

Basic set_regs()

The set_regs() method sets registers to specific values:

Example Output

Moving Registers

Using move_regs()

The move_regs() method copies values between registers:

Example Output

This chain moves the value from rdx into rax using intermediate gadgets.

Combining Chains

1

Set up initial values

2

Add more operations

3

View the complete chain

Complete Example

Preserving Registers

When calling functions, you can preserve specific registers:

Output

Notice that the first argument (0x41414141) is ignored because rdi is preserved, so the function will use whatever value is already in rdi.

Avoiding Bad Bytes

You can specify bad bytes to avoid in your chain:
angrop will automatically find alternative gadgets that don’t contain the specified bad bytes.

Real-World Example: Setting Up Syscall Arguments

Advanced: Register Arithmetic

You can also perform operations on registers:

Debugging Tips

Pretty Print

Use pp() to see exactly what each gadget does:

Payload Code

Use print_payload_code() to get ready-to-paste Python code:
This outputs code you can directly copy into your exploit script.

Chain Composition Patterns

Pattern 1: Setup, Execute, Cleanup

Pattern 2: Multi-Stage Chains

This modular approach makes complex chains easier to build and debug.