Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
rop-tool — Una herramienta para ayudarte a escribir exploits binarios. | Kitploit
Herramientas/GitHubGitHub/t00sh/rop-tool
ExplotaciónIngeniería InversaDepuradoresAnálisis de BinariosDesarrollo de PayloadsExplotación de Binarios
GitHubt00sh/rop-tool

rop-tool

Una herramienta para ayudarte a escribir exploits binarios.

Ver Repositorio
61210420hace 7 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

rop-tool v2.4.2

Una herramienta para ayudarte a escribir exploits binarios

OPCIONES

root@kitploit:~
rop-tool v2.4.2
Help you make binary exploits.

Usage: rop-tool <cmd> [OPTIONS]

Commands :
   gadget        Search gadgets
   patch         Patch the binary
   info          Print info about binary
   heap          Display heap structure
   disassemble   Disassemble the binary
   search        Search on binary
   help          Print help
   version       Print version

Try "rop-tool help <cmd>" for more informations about a command.

COMANDO GADGET

root@kitploit:~
Usage : rop-tool gadget [OPTIONS] [FILENAME]

OPTIONS:
  --arch, -A               Select an architecture (x86, x86-64, arm, arm64)
  --all, -a                Print all gadgets (even gadgets which are not uniq)
  --depth, -d         [d]  Specify the depth for gadget searching (default is 5)
  --flavor, -f        [f]  Select a flavor (att or intel)
  --no-filter, -F          Do not apply some filters on gadgets
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output

COMANDO SEARCH

Descargar herramienta
root@kitploit:~
Usage : rop-tool search [OPTIONS] [FILENAME]

OPTIONS:
  --all-string, -a    [n]  Search all printable strings of at least [n] caracteres. (default is 6)
  --byte, -b          [b]  Search the byte [b] in binary
  --dword, -d         [d]  Search the dword [d] in binary
  --help, -h               Print this help message
  --no-color, -N           Don't colorize output
  --qword, -q         [q]  Search the qword [q] in binary
  --raw, -r                Open file in raw mode (don't considere any file format)
  --split-string, -s  [s]  Search a string "splited" in memory (which is not contiguous in memory)
  --string, -S        [s]  Search a string (a byte sequence) in binary
  --word, -w          [w]  Search the word [w] in binary

COMANDO PATCH

root@kitploit:~
Usage : rop-tool patch [OPTIONS] [FILENAME]

OPTIONS:
  --address, -a       [a]  Select an address to patch
  --bytes, -b         [b]  A byte sequence (e.g. : "\xaa\xbb\xcc") to write
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --offset, -o        [o]  Select an offset to patch (from start of the file)
  --output, -O        [o]  Write to an another filename
  --raw, -r                Open file in raw mode

COMANDO INFO

root@kitploit:~
Usage : rop-tool info [OPTIONS] [FILENAME]

OPTIONS:
  --all, -a                Show all infos
  --segments, -l           Show segments
  --sections, -s           Show sections
  --syms, -S               Show symbols
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --no-color, -N           Disable colors

COMANDO DISASSEMBLE

root@kitploit:~
Usage : rop-tool dis [OPTIONS] [FILENAME]

OPTIONS:
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output
  --address, -a    <a>     Start disassembling at address <a>
  --offset, -o     <o>     Start disassembling at offset <o>
  --sym, -s        <s>     Disassemble symbol
  --len, -l        <l>     Disassemble only <l> bytes
  --arch, -A       <a>     Select architecture (x86, x86-64, arm, arm64)
  --flavor, -f     <f>     Change flavor (intel, att)

COMANDO HEAP

root@kitploit:~
Usage : rop-tool heap [OPTIONS] [COMMAND]

OPTIONS:
  --calloc, -C             Trace calloc calls
  --free, -F               Trace free calls
  --realloc, -R            Trace realloc calls
  --malloc, -M             Trace malloc calls
  --dumpdata, -d           Dump chunk's data
  --output, -O             Output in a file
  --help, -h               Print this help message
  --tmp, -t        <d>     Specify the writable directory, to dump the library (default: /tmp/)
  --no-color, -N           Do not colorize output

Pequeñas explicaciones sobre la salida del comando heap

Cada línea corresponde a un chunk de malloc, y el heap se vuelca después de cada ejecución de las funciones de heap (free, malloc, realloc, calloc)

  • addr: es la dirección real del chunk de malloc

  • usr_addr: es la dirección devuelta por las funciones de malloc al usuario

  • size: es el tamaño del chunk de malloc

  • flags: P es PREV_INUSE, M es IS_MAPED y A es NON_MAIN_ARENA

CARACTERÍSTICAS

  • Búsqueda de cadenas, búsqueda de gadgets, parcheo, información, visualización de heap, desensamblado

  • Salida coloreada

  • Sintaxis Intel y AT&T

  • Soporte de formato binario ELF, PE y MACH-O

  • Soporte de big y little endian

  • Soporte de arquitecturas x86, x86_64, ARM, ARM64, MIPS, MIPS64

EJEMPLOS

Búsqueda básica de gadgets

root@kitploit:~
rop-tool gadget ./program

Mostrar todos los gadgets con sintaxis AT&T

root@kitploit:~
rop-tool gadget ./program -f att -a

Buscar gadgets en un archivo RAW x86

root@kitploit:~
rop-tool gadget ./program -A x86

Buscar una cadena "dividida" en el binario

root@kitploit:~
rop-tool search ./program -s "/bin/sh"

Buscar todas las cadenas en el binario

root@kitploit:~
rop-tool search ./program -a

Parchear el binario en el offset 0x1000, con "\xaa\xbb\xcc\xdd" y guardar como "patched":

root@kitploit:~
rop-tool patch ./program -o 0x1000 -b "\xaa\xbb\xcc\xdd" -O patched

Visualizar la asignación de heap del comando /bin/ls:

root@kitploit:~
rop-tool heap /bin/ls

Desensamblar 0x100 bytes en la dirección 0x08048452

root@kitploit:~
rop-tool dis /bin/ls -l 0x100 -a 0x08048452

CAPTURAS DE PANTALLA

root@kitploit:~
rop-tool gadget /bin/ls

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -a

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -s "/bin/sh\x00"

ScreenShot

root@kitploit:~
rop-tool heap ./a.out

ScreenShot

root@kitploit:~
rop-tool dis ./bin  # Many formats

ScreenShot

COMPILACIÓN

root@kitploit:~
git clone https://github.com/t00sh/rop-tool.git
cd rop-tool
sh scripts/set_env.sh
make

DEPENDENCIAS

  • capstone

LICENCIA

  • Licencia GPLv3

AUTOR

Tosh (tosh at t0x0sh . org)