Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Ropper — さまざまなファイル形式のファイルに関する情報を表示し、異なるアーキテクチャ(x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64)のROPチェーンを構築するためのガジェットを見つけます。逆アセンブルには、Ropperは優れたCapstone Frameworkを使用しています。 | Kitploit
ツール/GitHubGitHub/sashs/ropper
ペイロード生成エクスプロイトリバースエンジニアリングCTFバイナリ解析バイナリエクスプロイトバイナリ解析 第19位バイナリエクスプロイト 第6位CTF 第9位リバースエンジニアリング 第17位
2.1k223601ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHubsashs/ropper

Ropper

さまざまなファイル形式のファイルに関する情報を表示し、異なるアーキテクチャ(x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64)のROPチェーンを構築するためのガジェットを見つけます。逆アセンブルには、Ropperは優れたCapstone Frameworkを使用しています。

リポジトリを見るウェブサイト

Ropper

Build Status

Ropper を使用すると、さまざまなファイル形式のバイナリファイルに関する情報を表示したり、さまざまなアーキテクチャ(x86/X86_64、ARM/ARM64、MIPS/MIPS64、PowerPC/PowerPC64、SPARC64)向けのROPチェーンを構築するためのガジェットを検索できます。逆アセンブルには、素晴らしい Capstone Framework を使用しています。

インストール

Capstone を PyPi でインストール:

$ sudo pip install capstone

filebytes を PyPi でインストール:

$ sudo pip install filebytes

オプション(Ropperの実行には不要、ガジェット検索のみに必要):

Keystone をインストール:

$ sudo pip install keystone-engine

Ropper をインストールして実行

$ python setup.py install
$ ropper

pip で Ropper をインストールすることもできます

$ pip install ropper

お望みなら、インストールせずに Ropper を使用することもできます

$ ./Ropper.py

filebytes をインストールしたくない場合、filebytes は ropper リポジトリのサブモジュールです。つまり、filebytes と ropper のインストールは不要です。

$ git clone https://github.com/sashs/ropper.git
$ cd ropper
$ git submodule init
$ git submodule update
$ ./Ropper.py

この機能はまだ開発中です! Ropper にはセマンティック検索コマンドがあり、ガジェットを検索できます。

$ ropper --file <afile> --semantic "<any constraint>"

セマンティック検索を使用するには、以下のオプションの依存関係が必要です:

pyvex をインストール

$ sudo pip install pyvex

z3py をインストール

$ python scripts/mk_make.py
$ cd build
$ make
$ sudo make install

現在可能な制約

reg == reg     -  レジスタを別のレジスタに代入
reg == number  -  数値をレジスタに代入
reg == [reg]   -  メモリをレジスタに代入
reg += number/reg/[reg]
reg -= number/reg/[reg]
reg *= number/reg/[reg]
reg /= number/reg/[reg]

制約の例

eax==1 !ebx    - eax を 1 に設定し、ebx を破壊しないガジェットを検索

セマンティック検索

使い方

usage: Ropper.py [-h] [--help-examples] [-v] [--console]
             [-f <file> [<file> ...]] [-r] [-a <arch>]
             [--section <section>] [--string [<string>]] [--hex]
             [--asm [<asm> [H|S|R] ...]] [--disasm <opcode>]
             [--disassemble-address <address:length>] [-i] [-e]
             [--imagebase] [-c] [-s] [-S] [--imports] [--symbols]
             [--set <option>] [--unset <option>] [-I <imagebase>] [-p]
             [-j <reg>] [--stack-pivot] [--inst-count <n bytes>]
             [--search <regex>] [--quality <quality>] [--opcode <opcode>]
             [--instructions <instructions>] [--type <type>] [--detailed]
             [--all] [--cfg-only] [--chain <generator>] [-b <badbytes>]
             [--nocolor] [--clear-cache] [--no-load] [--analyse <quality>]
             [--semantic constraint]
             [--count-of-findings <count of gadgets>] [--single]

You can use ropper to display information about binary files in different file formats
    and you can search for gadgets to build rop chains for different architectures

supported filetypes:
  ELF
  PE
  Mach-O
  Raw

supported architectures:
  x86 [x86]
  x86_64 [x86_64]
  MIPS [MIPS, MIPS64]
  ARM/Thumb [ARM, ARMTHUMB]
  ARM64 [ARM64]
  PowerPC [PPC, PPC64]
  SPARC [SPARC64]

available rop chain generators:
  execve (execve[=<cmd>], default /bin/sh) [Linux x86, x86_64]
  mprotect  (mprotect=<address>:<size>) [Linux x86, x86_64]
  virtualprotect (virtualprotect=<address iat vp>:<size>) [Windows x86]

options:
  -h, --help            show this help message and exit
  --help-examples       Print examples
  -v, --version         Print version
  --console             Starts interactive commandline
  -f <file> [<file> ...], --file <file> [<file> ...]
                        The file to load
  -r, --raw             Loads the file as raw file
  -a <arch>, --arch <arch>
                        The architecture of the loaded file
  --section <section>   The data of this section should be printed
  --string [<string>]   Looks for the string <string> in all data sections
  --hex                 Prints the selected sections in a hex format
  --asm [<asm> [H|S|R] ...]
                        A string to assemble and a format of the output
                        (H=HEX, S=STRING, R=RAW, default: H)
  --disasm <opcode>     Opcode to disassemble (e.g. ffe4, 89c8c3, ...)
  --disassemble-address <address:length>
                        Disassembles instruction at address <address>
                        (0x12345678:L3). The count of instructions to
                        disassemble can be specified (0x....:L...)
  -i, --info            Shows file header [ELF/PE/Mach-O]
  -e                    Shows EntryPoint
  --imagebase           Shows ImageBase [ELF/PE/Mach-O]
  -c, --dllcharacteristics
                        Shows DllCharacteristics [PE]
  -s, --sections        Shows file sections [ELF/PE/Mach-O]
  -S, --segments        Shows file segments [ELF/Mach-O]
  --imports             Shows imports [ELF/PE]
  --symbols             Shows symbols [ELF]
  --set <option>        Sets options. Available options: aslr nx
  --unset <option>      Unsets options. Available options: aslr nx
  -I <imagebase>        Use this imagebase for gadgets
  -p, --ppr             Searches for 'pop reg; pop reg; ret' instructions
                        [only x86/x86_64]
  -j <reg>, --jmp <reg>
                        Searches for 'jmp reg' instructions (-j reg[,reg...])
                        [only x86/x86_64]
  --stack-pivot         Prints all stack pivot gadgets
  --inst-count <n bytes>
                        Specifies the max count of instructions in a gadget
                        (default: 6)
  --search <regex>      Searches for gadgets
  --quality <quality>   The quality for gadgets which are found by search (1 =
                        best)
  --opcode <opcode>     Searches for opcodes (e.g. ffe4 or ffe? or ff??)
  --instructions <instructions>
                        Searches for instructions (e.g. "jmp esp", "pop eax;
                        ret")
  --type <type>         Sets the type of gadgets [rop, jop, sys, all]
                        (default: all)
  --detailed            Prints gadgets more detailed
  --all                 Does not remove duplicate gadgets
  --cfg-only            Filters out gadgets which fail the Microsoft CFG
                        check. Only for PE files which are compiled with CFG
                        check enabled (check DllCharachteristics) [PE]
  --chain <generator>   Generates a ropchain [generator parameter=value[
                        parameter=value]]
  -b <badbytes>, --badbytes <badbytes>
                        Set bytes which should not be contained in gadgets
  --nocolor             Disables colored output
  --clear-cache         Clears the cache
  --no-load             Don't load the gadgets automatically when starting the
                        console (--console)
  --analyse <quality>   just used for the implementation of semantic search
  --semantic constraint
                        semantic search for gadgets
  --count-of-findings <count of gadgets>
                        Max count of gadgets which will be printed with
                        semantic search (0 = undefined, default: 5)
  --single              No multiple processes are used for gadget scanning

example uses:
  [Generic]
  ./Ropper.py
  ./Ropper.py --file /bin/ls --console
ツールをダウンロード