ropshell> use 00dfcfa3da8c5e7c15e89a1a2ed510d6 (download)
name         : ntdll.dll (i386/PE)
base address : 0x4b281000
total gadgets: 12442
ropshell> suggest "stack pivoting"
> 0x4b2b2a6d : xchg eax, esp; ret
> 0x4b32b7c6 : xchg esp, edi; dec ecx; ret
> 0x4b2b36bb : mov esp, ebx; pop ebx; ret
> 0x4b2a65e4 : mov esp, ebp; pop ebp; ret
> 0x4b2d8500 : lea esp, [edx + 0x48d4b39]; ret
> 0x4b308d38 : lea esp, [esp + 0x80]; pop ecx; ret
> 0x4b2f1de6 : mov esp, esi; pop ebx; pop edi; pop esi; pop ebp; ret 0x10
> 0x4b2d6b25 : lea esp, [edi + edi*8 - 1]; jmp [eax]
> 0x4b2e6c1f : lea esp, [ecx + edi*8 - 1]; dec [ebx + 0x33c28bf7]; dec [ecx - 0x69f4b]; jmp [ecx]
> 0x4b2a5c1e : leave ; ret