Skip to main content

Getting Started with angrop

This guide will walk you through using angrop to find gadgets and build ROP chains. We’ll cover both the command-line interface and the Python API.

Using the CLI

The angrop-cli command provides quick access to basic gadget finding and chain building.

Finding Gadgets

To dump all gadgets in a binary:
The true/false indicator shows whether the gadget is self-contained (doesn’t depend on previous register state).

Building Predefined Chains

Generate an execve chain:
You can copy this output directly into your exploit!

Using the Python API

The Python API provides much more power and flexibility. Here’s how to use it.

Basic Setup

1

Import and create project

2

Find gadgets

This will show a progress bar while finding gadgets using multiple processes.
3

Build a chain

Complete Example

Here’s a complete working example:

Common Chain Building Patterns

Setting Registers

Moving Registers

Writing to Memory

Calling Functions

Invoking Syscalls

Generating execve Chains

Chaining Operations

You can chain multiple operations together using +:

Debugging Chains

Use pp() to pretty-print a chain for debugging:

Configuration Options

Customize the ROP analysis with configuration options:
fast_mode defaults to None, which automatically decides based on binary size. For large binaries, it enables fast mode to skip gadgets with conditional branches, floating point operations, and jumps.

Bad Bytes

Avoid bad bytes in your chain:

Advanced Example: Kernel Exploitation

Here’s a real-world example for Linux kernel container escape:

Performance Tips

Use Caching

Adjust Process Count

Optimize After Finding

Use Fast Mode

Next Steps

Now that you know the basics: