Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
rop-tool — Инструмент для написания бинарных эксплойтов | Kitploit
Инструменты/GitHubGitHub/t00sh/rop-tool
ЭксплуатацияОбратная инженерияОтладчикиАнализ Бинарных ФайловРазработка Полезной НагрузкиЭксплуатация Бинарных Файлов
GitHubt00sh/rop-tool

rop-tool

Инструмент для написания бинарных эксплойтов

Репозиторий
6121047 лет назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

rop-tool v2.4.2

Инструмент для помощи в написании бинарных эксплойтов

OPTIONS

root@kitploit:~
rop-tool v2.4.2
Help you make binary exploits.

Usage: rop-tool <cmd> [OPTIONS]

Commands :
   gadget        Search gadgets
   patch         Patch the binary
   info          Print info about binary
   heap          Display heap structure
   disassemble   Disassemble the binary
   search        Search on binary
   help          Print help
   version       Print version

Try "rop-tool help <cmd>" for more informations about a command.

КОМАНДА GADGET

root@kitploit:~
Usage : rop-tool gadget [OPTIONS] [FILENAME]

OPTIONS:
  --arch, -A               Select an architecture (x86, x86-64, arm, arm64)
  --all, -a                Print all gadgets (even gadgets which are not uniq)
  --depth, -d         [d]  Specify the depth for gadget searching (default is 5)
  --flavor, -f        [f]  Select a flavor (att or intel)
  --no-filter, -F          Do not apply some filters on gadgets
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output

КОМАНДА SEARCH

root@kitploit:~
Usage : rop-tool search [OPTIONS] [FILENAME]

OPTIONS:
  --all-string, -a    [n]  Search all printable strings of at least [n] caracteres. (default is 6)
  --byte, -b          [b]  Search the byte [b] in binary
  --dword, -d         [d]  Search the dword [d] in binary
  --help, -h               Print this help message
  --no-color, -N           Don't colorize output
  --qword, -q         [q]  Search the qword [q] in binary
  --raw, -r                Open file in raw mode (don't considere any file format)
  --split-string, -s  [s]  Search a string "splited" in memory (which is not contiguous in memory)
  --string, -S        [s]  Search a string (a byte sequence) in binary
  --word, -w          [w]  Search the word [w] in binary

КОМАНДА PATCH

root@kitploit:~
Usage : rop-tool patch [OPTIONS] [FILENAME]

OPTIONS:
  --address, -a       [a]  Select an address to patch
  --bytes, -b         [b]  A byte sequence (e.g. : "\xaa\xbb\xcc") to write
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --offset, -o        [o]  Select an offset to patch (from start of the file)
  --output, -O        [o]  Write to an another filename
  --raw, -r                Open file in raw mode

КОМАНДА INFO

root@kitploit:~
Usage : rop-tool info [OPTIONS] [FILENAME]

OPTIONS:
  --all, -a                Show all infos
  --segments, -l           Show segments
  --sections, -s           Show sections
  --syms, -S               Show symbols
  --filename, -f      [f]  Specify the filename
  --help, -h               Print this help message
  --no-color, -N           Disable colors

КОМАНДА DISASSEMBLE

root@kitploit:~
Usage : rop-tool dis [OPTIONS] [FILENAME]

OPTIONS:
  --help, -h               Print this help message
  --no-color, -N           Do not colorize output
  --address, -a    <a>     Start disassembling at address <a>
  --offset, -o     <o>     Start disassembling at offset <o>
  --sym, -s        <s>     Disassemble symbol
  --len, -l        <l>     Disassemble only <l> bytes
  --arch, -A       <a>     Select architecture (x86, x86-64, arm, arm64)
  --flavor, -f     <f>     Change flavor (intel, att)

КОМАНДА HEAP

root@kitploit:~
Usage : rop-tool heap [OPTIONS] [COMMAND]

OPTIONS:
  --calloc, -C             Trace calloc calls
  --free, -F               Trace free calls
  --realloc, -R            Trace realloc calls
  --malloc, -M             Trace malloc calls
  --dumpdata, -d           Dump chunk's data
  --output, -O             Output in a file
  --help, -h               Print this help message
  --tmp, -t        <d>     Specify the writable directory, to dump the library (default: /tmp/)
  --no-color, -N           Do not colorize output

Небольшие пояснения о выводе команды heap

Каждая строка соответствует chunke malloc, и куча дампится после каждого вызова функций кучи (free, malloc, realloc, calloc)

  • addr: это реальный адрес chunka malloc

  • usr_addr: это адрес, возвращаемый пользователю функциями malloc

  • size: это размер chunka malloc

  • flags: P — PREV_INUSE, M — IS_MAPED, A — NON_MAIN_ARENA

ВОЗМОЖНОСТИ

  • Поиск строк, поиск гаджетов, патчинг, информация, визуализация кучи, дизассемблирование
  • Цветной вывод
  • Синтаксис Intel и AT&T
  • Поддержка бинарных форматов ELF, PE и MACH-O
  • Поддержка big и little endian
  • Поддержка архитектур x86, x86_64, ARM, ARM64, MIPS, MIPS64

ПРИМЕРЫ

Базовый поиск гаджетов

root@kitploit:~
rop-tool gadget ./program

Отображение всех гаджетов с синтаксисом AT&T

root@kitploit:~
rop-tool gadget ./program -f att -a

Поиск гаджетов в RAW файле x86

root@kitploit:~
rop-tool gadget ./program -A x86

Поиск «разделённой» строки в бинарнике

root@kitploit:~
rop-tool search ./program -s "/bin/sh"

Поиск всех строк в бинарнике

root@kitploit:~
rop-tool search ./program -a

Патч бинарника по смещению 0x1000, с данными "\xaa\xbb\xcc\xdd" и сохранение в файл "patched":

root@kitploit:~
rop-tool patch ./program -o 0x1000 -b "\xaa\xbb\xcc\xdd" -O patched

Визуализация распределения кучи для команды /bin/ls:

root@kitploit:~
rop-tool heap /bin/ls

Дизассемблирование 0x100 байт по адресу 0x08048452

root@kitploit:~
rop-tool dis /bin/ls -l 0x100 -a 0x08048452

СКРИНШОТЫ

root@kitploit:~
rop-tool gadget /bin/ls

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -a

ScreenShot

root@kitploit:~
rop-tool search /bin/ls -s "/bin/sh\x00"

ScreenShot

root@kitploit:~
rop-tool heap ./a.out

ScreenShot

root@kitploit:~
rop-tool dis ./bin  # Many formats

ScreenShot

КОМПИЛЯЦИЯ

root@kitploit:~
git clone https://github.com/t00sh/rop-tool.git
cd rop-tool
sh scripts/set_env.sh
make

ЗАВИСИМОСТИ

  • capstone

ЛИЦЕНЗИЯ

  • Лицензия GPLv3

АВТОР

Tosh (tosh at t0x0sh . org)

Скачать инструмент