Skip to main content
Angrop automatically generates ROP chains by combining gadgets to achieve your desired operations. This guide covers how to build and compose chains effectively.

Chain Composition with the + Operator

One of angrop’s most powerful features is the ability to compose chains using the + operator. This allows you to build complex exploits step by step.

Basic Chain Composition

Multi-Step Exploit Example

This example shows building a complete exploit chain that opens and reads a file:
Each chain operation returns a RopChain object that can be combined with other chains using +. The resulting chain maintains all constraints and ensures correct execution order.

Real-World Example: Linux Kernel Escape

This example from angrop’s test suite demonstrates composing a sophisticated kernel privilege escalation chain:

Breaking Down the Chain

Let’s examine what each step accomplishes:
1

Escalate privileges

Calls commit_creds() with init_cred to gain root privileges.
2

Find init process

Finds the init process (PID 1). The return value goes to rax.
3

Move return value to argument register

Moves the task struct pointer from rax to rdi for the next call.
4

Set up additional arguments

Sets rsi to init_nsproxy while preserving the rdi value we just set.
5

Switch namespaces

Calls the function using the preserved register values.
6

Fork and sleep

Creates a new process and sleeps to maintain the exploit.
When composing chains, use preserve_regs to maintain register values across multiple function calls. This is essential for passing return values or maintaining state.

Chain Inspection and Debugging

Angrop provides methods to inspect and debug your chains before using them:

Pretty-Print Chains

Output:

Generate Exploit Code

Output:

Get Raw Bytes

Incremental Chain Building

You can build chains incrementally, adding operations as needed:

Chain Optimization

Angrop automatically optimizes chains during generation, but you can influence the process:

Minimize Stack Usage

Avoid Register Clobbering

Error Handling

When chain building fails, angrop raises RopException with details:

Advanced Composition Patterns

Conditional Chains

Repeated Operations

When building large chains, consider breaking them into logical sections and testing each section independently before composing the final exploit.

Performance Considerations

  • Chain length: Longer chains may take more time to generate due to constraint solving
  • Preserve registers: Using preserve_regs adds constraints and may limit available gadgets
  • Badbytes: More badbytes increase chain generation complexity
  • Optimization: The initial find_gadgets(optimize=True) enables better chain composition

Next Steps

Now that you understand chain composition, explore specific operations: