Overview
After initializing a ROP analysis, you need to find gadgets before you can build chains. Angrop offers three main approaches:- Multithreaded search - Fast gadget discovery using multiple processes
- Single-threaded search - Useful for performance evaluation and debugging
- Load from cache - Reuse previously discovered gadgets
Finding Gadgets with Multiprocessing
Thefind_gadgets() method searches for gadgets using multiple processes for optimal performance.
Method Signature
optimize(bool): Whether to runchain_builder.optimize()after finding gadgets. This may take time but makes the chain builder more powerful. Default isTrue.processes(int): Number of processes to use for multiprocessing. Default is4.show_progress(bool): Whether to display a progress bar. Default isTrue.
Example Usage
1
Initialize the ROP analysis
2
Find gadgets with default settings
3
Customize the search parameters
The
optimize parameter runs graph optimization algorithms that discover additional ROP capabilities by chaining gadgets together. While this increases setup time, it significantly improves chain generation success rates.Finding Gadgets Single-Threaded
Thefind_gadgets_single_threaded() method is useful for performance evaluation and debugging.
Method Signature
show_progress(bool): Whether to display a progress bar. Default isTrue.optimize(bool): Whether to run optimization. Default isTrue.
Example Usage
Saving and Loading Gadgets
For large binaries, gadget discovery can take significant time. Angrop supports caching gadgets to disk.Saving Gadgets
path(str): File path where gadgets will be stored using pickle format.
Loading Gadgets
path(str): File path from which to load gadgets.optimize(bool): Whether to run optimization after loading. Default isTrue.
Example: Cache-First Workflow
The cache files are specific to the binary and configuration parameters. If you change
ROP() initialization parameters (like kernel_mode, fast_mode, etc.), you should regenerate the cache.Real-World Example: Linux Kernel Gadgets
This example from angrop’s test suite shows a complete workflow for finding gadgets in the Linux kernel:What Happens During Gadget Finding
When you callfind_gadgets() or find_gadgets_single_threaded(), angrop:
- Identifies potential gadget locations - Scans for return instructions and nearby code
- Analyzes each gadget - Symbolically executes instruction sequences to determine their effects
- Categorizes gadgets - Sorts them into:
rop_gadgets- General-purpose ROP gadgets (pop, mov, arithmetic, etc.)syscall_gadgets- Gadgets ending in syscall/int 0x80pivot_gadgets- Stack pivoting gadgets
- Filters by badbytes - Removes gadgets whose addresses contain badbytes (if configured)
- Optimizes chains (if enabled) - Discovers complex multi-gadget capabilities