Getting Started with angrop
This guide will walk you through using angrop to find gadgets and build ROP chains. We’ll cover both the command-line interface and the Python API.Using the CLI
Theangrop-cli command provides quick access to basic gadget finding and chain building.
Finding Gadgets
To dump all gadgets in a binary:true/false indicator shows whether the gadget is self-contained (doesn’t depend on previous register state).
Building Predefined Chains
Generate anexecve chain:
Using the Python API
The Python API provides much more power and flexibility. Here’s how to use it.Basic Setup
1
Import and create project
2
Find gadgets
3
Build a chain
Complete Example
Here’s a complete working example:Common Chain Building Patterns
Setting Registers
Moving Registers
Writing to Memory
Calling Functions
Invoking Syscalls
Generating execve Chains
Chaining Operations
You can chain multiple operations together using+:
Debugging Chains
Usepp() to pretty-print a chain for debugging:
Configuration Options
Customize the ROP analysis with configuration options:fast_mode defaults to None, which automatically decides based on binary size. For large binaries, it enables fast mode to skip gadgets with conditional branches, floating point operations, and jumps.Bad Bytes
Avoid bad bytes in your chain:Advanced Example: Kernel Exploitation
Here’s a real-world example for Linux kernel container escape:Performance Tips
Use Caching
Adjust Process Count
Optimize After Finding
Use Fast Mode
Next Steps
Now that you know the basics:- Explore the ROP class API and Chain Builder API for all available methods
- Check out Examples for real-world use cases
- Read about advanced features like SROP, stack pivoting, and memory operations