ropshell> use 1a40c3f362d7f068d2a744b541e6c887 (download) name : winbox.exe (i386/PE) base address : 0x401000 total gadgets: 35665
ropshell> suggest "load reg" > 0x0040a2b9 : pop eax; ret > 0x004b98bb : pop ebx; ret > 0x004c94c8 : pop ecx; ret > 0x004b108f : pop edx; ret > 0x0046126a : pop esi; ret > 0x0045b85d : pop edi; ret > 0x00401fd4 : pop ebp; ret > 0x0050aa6b : popal ; ret > 0x00480548 : pop esp; pop ebp; ret 4 > 0x004c88a0 : mov eax, [esp + 4]; ret > 0x00507e7d : mov edx, [esp + 0x30]; mov [eax], edx; add esp, 0x2c; ret 4 > 0x004bf749 : mov ecx, [esp + 0x50]; mov [esp], edi; call ebp > 0x004bedcb : mov esi, [esp + 0x24]; mov eax, [ecx]; mov [esp], esi; call [eax]