# Binary Exploitation Rop

> Use when writing binary exploits and ROP chains.

- Skill: `loopyluci/binary-exploitation-rop` (Agent Skill)
- Install (CLI): `npx skillmds@latest add loopyluci/binary-exploitation-rop`
- Raw SKILL.md: https://api.skillmd.com/api/skills/loopyluci/binary-exploitation-rop/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: MIT
- Author: LoopyLuci (https://skillmd.com/u/loopyluci)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/loopyluci/binary-exploitation-rop

---


# Binary Exploitation and ROP

Writing binary exploits — from stack pivoting and ROP chains through ASLR bypass, ret2libc, format string exploitation, and modern mitigation bypass.

## When to Use

- Writing ROP chains for bypassing DEP/NX
- Bypassing modern memory protections (ASLR, Stack Canary, RELRO, PIE)
- Building reliable exploits across different libc versions
- Format string exploitation for memory read/write

## ROP Chain Construction

```python
ROP_TECHNIQUES = {
    'ret2libc': "Overwrite return with system()@libc + '/bin/sh' argument",
    'ret2plt': "Call PLT-resolved functions (no need for ASLR leak)",
    'ret2csu': "Universal x64 gadgets from __libc_csu_init (__libc_csu_init gadgets)",
    'sigreturn': "Sigreturn Oriented Programming (SROP) — set all registers via sigreturn",
    'stack_pivot': "Set RSP to controlled buffer when stack is too small",
}

# ropper / ROPgadget
ROP_GADGET_SEARCH = """
# Find gadgets with ROPgadget
$ ROPgadget --binary vulnerable --only 'pop|ret' | grep 'pop rdi'
$ ROPgadget --binary vulnerable --only 'syscall|ret'

# ropper
$ ropper --file vulnerable --search "pop rdi"
"""

# Format string leak
FORMAT_STRING_EXPLOIT = """
# Leak stack values
%s %x %lx %p ... %n (for arbitrary write)

# Write to GOT entry to overwrite function pointer
$ ./vuln "$(python3 -c 'import sys; sys.stdout.buffer.write(b"%64\$hnAAAA" + p64(got_entry))')"
"""
```

## Verification Checklist

- [ ] Mitigations checked (checksec): NX, ASLR, Canary, PIE, RELRO, Fortify
- [ ] Offset to EIP/RIP identified
- [ ] ROP gadgets found for target environment (libc version)
- [ ] libc base address leaked (format string, unsorted bin, or partial overwrite)
- [ ] ROP chain built (pop rdi → /bin/sh → system() or execve() syscall)
- [ ] Exploit reliable across multiple runs (address stability)
- [ ] Tested in target environment (same libc version, kernel version)
- [ ] One_gadget checked for simpler exploitation

