Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
rop-tool — Uno strumento per aiutarti a scrivere exploit binari | Kitploit
Strumenti/GitHubGitHub/t00sh/rop-tool
ExploitReverse EngineeringDebuggerAnalisi di BinariSviluppo PayloadBinary Exploitation
GitHubt00sh/rop-tool

rop-tool

Uno strumento per aiutarti a scrivere exploit binari

Vedi Repository
6121047 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

rop-tool v2.4.2

Uno strumento per aiutarti a scrivere exploit binari

OPZIONI

root@kitploit:~
rop-tool v2.4.2
Help you make binary exploits.

Usage: rop-tool <cmd> [OPTIONS]

Commands :
   gadget        Search gadgets
   patch         Patch the binary
   info          Print info about binary
   heap          Display heap structure
   disassemble   Disassemble the binary
   search        Search on binary
   help          Print help
   version       Print version

Try "rop-tool help <cmd>" for more informations about a command.

COMANDO GADGET

root@kitploit:~
Usage : rop-tool gadget [OPTIONS] [FILENAME]

OPTIONS:
  --arch, -A               Select an architecture (x86, x86-64, arm, arm64)
  --all, -a                Print all gadgets (even gadgets which are not uniq)
  --depth, -d         [d]  Specify the depth for gadget searching (default is 5)
  --flavor, -f        [f]  Select a flavor (att or intel)
  --no-filter, -F          Do not apply some filters on gadgets
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output

COMANDO RICERCA

root@kitploit:~
Usage : rop-tool search [OPTIONS] [FILENAME]

OPTIONS:
  --all-string, -a    [n]  Search all printable strings of at least [n] caracteres. (default is 6)
  --byte, -b          [b]  Search the byte [b] in binary
  --dword, -d         [d]  Search the dword [d] in binary
  --help, -h               Print this help message
  --no-color, -N           Don't colorize output
  --qword, -q         [q]  Search the qword [q] in binary
  --raw, -r                Open file in raw mode (don't considere any file format)
  --split-string, -s  [s]  Search a string "splited" in memory (which is not contiguous in memory)
  --string, -S        [s]  Search a string (a byte sequence) in binary
  --word, -w          [w]  Search the word [w] in binary

COMANDO PATCH

root@kitploit:~
Usage : rop-tool patch [OPTIONS] [FILENAME]

OPTIONS:
  --address, -a       [a]  Select an address to patch
  --bytes, -b         [b]  A byte sequence (e.g. : "\xaa\xbb\xcc") to write
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --offset, -o        [o]  Select an offset to patch (from start of the file)
  --output, -O        [o]  Write to an another filename
  --raw, -r                Open file in raw mode

COMANDO INFO

root@kitploit:~
Usage : rop-tool info [OPTIONS] [FILENAME]

OPTIONS:
  --all, -a                Show all infos
  --segments, -l           Show segments
  --sections, -s           Show sections
  --syms, -S               Show symbols
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --no-color, -N           Disable colors

COMANDO DISASSEMBLE

root@kitploit:~
Usage : rop-tool dis [OPTIONS] [FILENAME]

OPTIONS:
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output
  --address, -a    <a>     Start disassembling at address <a>
  --offset, -o     <o>     Start disassembling at offset <o>
  --sym, -s        <s>     Disassemble symbol
  --len, -l        <l>     Disassemble only <l> bytes
  --arch, -A       <a>     Select architecture (x86, x86-64, arm, arm64)
  --flavor, -f     <f>     Change flavor (intel, att)

COMANDO HEAP

root@kitploit:~
Usage : rop-tool heap [OPTIONS] [COMMAND]

OPTIONS:
  --calloc, -C             Trace calloc calls
  --free, -F               Trace free calls
  --realloc, -R            Trace realloc calls
  --malloc, -M             Trace malloc calls
  --dumpdata, -d           Dump chunk's data
  --output, -O             Output in a file
  --help, -h               Print this help message
  --tmp, -t        <d>     Specify the writable directory, to dump the library (default: /tmp/)
  --no-color, -N           Do not colorize output

Piccole spiegazioni sull'output del comando heap

Ogni riga corrisponde a un chunk malloc, e l'heap viene dumpato dopo ogni esecuzione delle funzioni heap (free, malloc, realloc, calloc)

  • addr: è l'indirizzo reale del chunk malloc

  • usr_addr: è l'indirizzo restituito dalle funzioni malloc all'utente

  • size: è la dimensione del chunk malloc

  • flags: P è PREV_INUSE, M è IS_MAPED e A è NON_MAIN_ARENA

CARATTERISTICHE

  • Ricerca di stringhe, ricerca di gadget, patching, info, visualizzazione heap, disassemblaggio

  • Output colorato

  • Flavors Intel e AT&T

  • Supporto dei formati binari ELF, PE e MACH-O

  • Supporto di big e little endian

  • Supporto delle architetture x86, x86_64, ARM, ARM64, MIPS, MIPS64

ESEMPI

Ricerca base di gadget

root@kitploit:~
rop-tool gadget ./program

Mostra tutti i gadget con sintassi AT&T

root@kitploit:~
rop-tool gadget ./program -f att -a

Cerca gadget in file RAW x86

root@kitploit:~
rop-tool gadget ./program -A x86

Cerca una stringa "divisa" nel binario

root@kitploit:~
rop-tool search ./program -s "/bin/sh"

Cerca tutte le stringhe nel binario

root@kitploit:~
rop-tool search ./program -a

Applica patch al binario all'offset 0x1000, con "\xaa\xbb\xcc\xdd" e salva come "patched":

root@kitploit:~
rop-tool patch ./program -o 0x1000 -b "\xaa\xbb\xcc\xdd" -O patched

Visualizza l'allocazione heap del comando /bin/ls:

root@kitploit:~
rop-tool heap /bin/ls

Disassembla 0x100 byte all'indirizzo 0x08048452

root@kitploit:~
rop-tool dis /bin/ls -l 0x100 -a 0x08048452

SCREENSHOT

root@kitploit:~
rop-tool gadget /bin/ls

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -a

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -s "/bin/sh\x00"

ScreenShot

root@kitploit:~
rop-tool heap ./a.out

ScreenShot

root@kitploit:~
rop-tool dis ./bin  # Many formats

ScreenShot

COMPILAZIONE

root@kitploit:~
git clone https://github.com/t00sh/rop-tool.git
cd rop-tool
sh scripts/set_env.sh
make

DIPENDENZE

  • capstone

LICENZA

  • GPLv3 license

AUTORE

Tosh (tosh at t0x0sh . org)

Scarica lo strumento