Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
rop-tool — バイナリエクスプロイトを作成するためのツール | Kitploit
ツール/GitHubGitHub/t00sh/rop-tool
エクスプロイトリバースエンジニアリングデバッガバイナリ解析ペイロード開発バイナリエクスプロイト
GitHubt00sh/rop-tool

rop-tool

バイナリエクスプロイトを作成するためのツール

リポジトリを見る
6121047年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

rop-tool v2.4.2

バイナリエクスプロイト作成を支援するツール

オプション

root@kitploit:~
rop-tool v2.4.2
Help you make binary exploits.

Usage: rop-tool <cmd> [OPTIONS]

Commands :
   gadget        Search gadgets
   patch         Patch the binary
   info          Print info about binary
   heap          Display heap structure
   disassemble   Disassemble the binary
   search        Search on binary
   help          Print help
   version       Print version

Try "rop-tool help <cmd>" for more informations about a command.

GADGET コマンド

root@kitploit:~
Usage : rop-tool gadget [OPTIONS] [FILENAME]

OPTIONS:
  --arch, -A               Select an architecture (x86, x86-64, arm, arm64)
  --all, -a                Print all gadgets (even gadgets which are not uniq)
  --depth, -d         [d]  Specify the depth for gadget searching (default is 5)
  --flavor, -f        [f]  Select a flavor (att or intel)
  --no-filter, -F          Do not apply some filters on gadgets
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output

SEARCH コマンド

root@kitploit:~
Usage : rop-tool search [OPTIONS] [FILENAME]

OPTIONS:
  --all-string, -a    [n]  Search all printable strings of at least [n] caracteres. (default is 6)
  --byte, -b          [b]  Search the byte [b] in binary
  --dword, -d         [d]  Search the dword [d] in binary
  --help, -h               Print this help message
  --no-color, -N           Don't colorize output
  --qword, -q         [q]  Search the qword [q] in binary
  --raw, -r                Open file in raw mode (don't considere any file format)
  --split-string, -s  [s]  Search a string "splited" in memory (which is not contiguous in memory)
  --string, -S        [s]  Search a string (a byte sequence) in binary
  --word, -w          [w]  Search the word [w] in binary

PATCH コマンド

root@kitploit:~
Usage : rop-tool patch [OPTIONS] [FILENAME]

OPTIONS:
  --address, -a       [a]  Select an address to patch
  --bytes, -b         [b]  A byte sequence (e.g. : "\xaa\xbb\xcc") to write
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --offset, -o        [o]  Select an offset to patch (from start of the file)
  --output, -O        [o]  Write to an another filename
  --raw, -r                Open file in raw mode

INFO コマンド

root@kitploit:~
Usage : rop-tool info [OPTIONS] [FILENAME]

OPTIONS:
  --all, -a                Show all infos
  --segments, -l           Show segments
  --sections, -s           Show sections
  --syms, -S               Show symbols
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --no-color, -N           Disable colors

DISASSEMBLE コマンド

root@kitploit:~
Usage : rop-tool dis [OPTIONS] [FILENAME]

OPTIONS:
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output
  --address, -a    <a>     Start disassembling at address <a>
  --offset, -o     <o>     Start disassembling at offset <o>
  --sym, -s        <s>     Disassemble symbol
  --len, -l        <l>     Disassemble only <l> bytes
  --arch, -A       <a>     Select architecture (x86, x86-64, arm, arm64)
  --flavor, -f     <f>     Change flavor (intel, att)

HEAP コマンド

root@kitploit:~
Usage : rop-tool heap [OPTIONS] [COMMAND]

OPTIONS:
  --calloc, -C             Trace calloc calls
  --free, -F               Trace free calls
  --realloc, -R            Trace realloc calls
  --malloc, -M             Trace malloc calls
  --dumpdata, -d           Dump chunk's data
  --output, -O             Output in a file
  --help, -h               Print this help message
  --tmp, -t        <d>     Specify the writable directory, to dump the library (default: /tmp/)
  --no-color, -N           Do not colorize output

heap コマンドの出力についての簡単な説明

各行は malloc チャンクに対応し、ヒープ関数 (free, malloc, realloc, calloc) の実行ごとにヒープがダンプされます。

  • addr: malloc チャンクの実際のアドレス

  • usr_addr: malloc 関数がユーザーに返すアドレス

  • size: malloc チャンクのサイズ

  • flags: P は PREV_INUSE, M は IS_MAPED, A は NON_MAIN_ARENA

機能

  • 文字列検索、ガジェット検索、パッチ適用、情報表示、ヒープ可視化、逆アセンブル

  • カラー出力

  • Intel および AT&T フレーバー

  • ELF, PE, MACH-O バイナリ形式のサポート

  • ビッグエンディアンとリトルエンディアンのサポート

  • x86, x86_64, ARM, ARM64, MIPS, MIPS64 アーキテクチャのサポート

使用例

基本的なガジェット検索

root@kitploit:~
rop-tool gadget ./program

AT&T 構文ですべてのガジェットを表示

root@kitploit:~
rop-tool gadget ./program -f att -a

RAW x86 ファイル内のガジェットを検索

root@kitploit:~
rop-tool gadget ./program -A x86

バイナリ内の「分割された」文字列を検索

root@kitploit:~
rop-tool search ./program -s "/bin/sh"

バイナリ内のすべての文字列を検索

root@kitploit:~
rop-tool search ./program -a

オフセット 0x1000 でバイナリに "\xaa\xbb\xcc\xdd" を書き込み、"patched" として保存:

root@kitploit:~
rop-tool patch ./program -o 0x1000 -b "\xaa\xbb\xcc\xdd" -O patched

/bin/ls コマンドのヒープ割り当てを可視化:

root@kitploit:~
rop-tool heap /bin/ls

アドレス 0x08048452 で 0x100 バイトを逆アセンブル

root@kitploit:~
rop-tool dis /bin/ls -l 0x100 -a 0x08048452

スクリーンショット

root@kitploit:~
rop-tool gadget /bin/ls

スクリーンショット

root@kitploit:~
rop-tool search /bin/ls -a

スクリーンショット

root@kitploit:~
rop-tool search /bin/ls -s "/bin/sh\x00"

スクリーンショット

root@kitploit:~
rop-tool heap ./a.out

スクリーンショット

root@kitploit:~
rop-tool dis ./bin  # Many formats

スクリーンショット

コンパイル

root@kitploit:~
git clone https://github.com/t00sh/rop-tool.git
cd rop-tool
sh scripts/set_env.sh
make

依存関係

  • capstone

ライセンス

  • GPLv3 ライセンス

著者

Tosh (tosh at t0x0sh . org)

ツールをダウンロード