Skip to main content

Overview

This example demonstrates how to build a simple ROP chain that sets register values using set_regs(). This is one of the most fundamental operations in ROP chain construction.

Basic Register Setting

1

Initialize angrop

Load your binary and create a ROP analysis object:
2

Find gadgets

Search for ROP gadgets in the binary:
This analyzes the binary and identifies useful ROP gadgets that can be chained together.
3

Build the chain

Create a chain that sets specific register values:
4

Print the payload

Generate exploit code ready to copy into your script:

Complete Example

Expected Output

Understanding the Chain

  1. First gadget (0xf5e2): Pops values into rbx, r12, and rbp. We use this to set rbx to 0x42424242.
  2. Second gadget (0x812f): Pops a value into rsi. We use this to temporarily store 0x41414141 in rsi.
  3. Third gadget (0x169dd): Moves the value from rsi into rax, achieving our goal of setting rax to 0x41414141.

Debugging Chains

You can also pretty-print the chain for debugging:
This shows each gadget and its arguments in a readable format.

Setting Multiple Registers

You can set as many registers as needed in a single call:
angrop automatically finds the optimal gadget sequence to set all requested registers.