What are Badbytes?
Badbytes are byte values that cannot appear in your exploit payload due to input filtering or processing. Common examples:- Null bytes (
0x00) - Terminated by string functions likestrcpy,scanf - Newlines (
0x0a,0x0d) - Terminated by line-oriented input functions - Whitespace (
0x09,0x20) - Filtered by input parsing - Control characters - Stripped or modified by terminal handlers
- Application-specific - Custom filters in the target program
Badbytes can appear in:
- Gadget addresses - The address of the gadget itself
- Data values - Constants, strings, or pointers in the chain
- Intermediate values - Values created during chain execution
Configuring Badbytes: set_badbytes()
Use the set_badbytes() method to specify restricted bytes before finding gadgets.
Method Signature
badbytes: List of 8-bit integers (0-255) representing restricted bytes
Basic Examples
1
Set common badbytes
2
Set multiple badbytes
3
Use character values
Checking Configured Badbytes: get_badbytes()
Retrieve the current badbytes configuration:
How Badbyte Avoidance Works
Angrop uses multiple strategies to avoid badbytes:1. Gadget Address Filtering
From the source code (rop.py:72-97), when gadgets are found:
2. Value Construction via Arithmetic
When you need to set a register to a value containing badbytes, angrop constructs it using arithmetic operations:reg_setter.py:699-725), angrop tries:
- Concrete value gadgets - Gadgets that set registers to specific values
- Arithmetic chains - Using add/sub/xor/or/and to construct values
- Register moves - Moving from registers that can be safely set
3. Memory Write Transformations
When writing data containing badbytes to memory, angrop uses sophisticated multi-step transformations:mem_writer.py:213-250), angrop tries operations in order:
1
Try XOR transformation
2
Try OR transformation
3
Try AND transformation
4
Try ADD transformation
Real-World Example: Null-Free Exploit
Common Badbyte Scenarios
Scenario 1: strcpy Vulnerability
Scenario 2: Line-Based Input
Scenario 3: URL/HTTP Input
Scenario 4: Alphanumeric Shellcode
Troubleshooting Badbyte Issues
Issue 1: “Couldn’t set registers” Error
Cause: Too many badbytes make it impossible to construct required values. Solutions:Issue 2: “Fail to write data to memory” Error
Cause: Can’t construct memory write chain without badbytes. Solutions:Issue 3: Very Few Gadgets Found
Cause: Badbytes eliminate too many gadget addresses. Solutions:1
Check badbyte configuration
2
Use fast_mode=False
3
Check gadget availability
Issue 4: Addresses Contain Badbytes
Cause: The binary loads at addresses containing badbytes. Solutions:Advanced Badbyte Techniques
Technique 1: Register Arithmetic Chains
When direct register setting fails, use arithmetic:Technique 2: Memory Staging
Write data to memory in multiple stages:Technique 3: Gadget Equivalence
Angrop automatically finds equivalent gadgets at safe addresses:Best Practices
- Set badbytes early - Always before
find_gadgets() - Be conservative - Only restrict truly necessary bytes
- Test payloads - Verify no badbytes in final chain
- Cache gadgets - Save and reuse gadgets for same binary+badbytes
- Understand constraints - Know why bytes are restricted
- Have fallbacks - Plan alternative exploitation if chains fail
Testing for Badbytes
Performance Impact
Badbyte restrictions affect performance:- Gadget finding: Slower as more gadgets are filtered
- Chain building: May require longer chains to avoid badbytes
- Optimization: More complex constraint solving
Badbyte Limitations
When Badbyte Avoidance Fails
Some situations make badbyte-free chains impossible:- Binary base contains badbytes - Non-PIE binary at bad address
- Too many badbytes - Overly restrictive filter (e.g., alphanumeric-only)
- Required values contain badbytes - Specific addresses or constants needed
- Insufficient gadgets - Not enough safe gadgets available
Alternative Approaches
When angrop can’t generate badbyte-free chains:Next Steps
- Memory Operations - See how badbytes affect memory writes
- Register Operations - Understand arithmetic value construction
- Optimization - Learn about gadget optimization with badbytes