ropshell> use 4813ac1e979171c5d472e9c4cead3af1 (download) name : SmackW32.dll (i386/PE) base address : 0x10001000 total gadgets: 1828
ropshell> suggest "load mem" > 0x1000a970 : mov edx, [ecx]; sub eax, edx; ret > 0x1000892b : mov eax, [ebx]; push eax; call edi > 0x10007133 : mov eax, [ebx + 4]; pop edi; pop esi; pop ebx; ret 0xc > 0x1000946b : mov eax, [ecx]; call [eax + 0x30] > 0x10009448 : mov eax, [edx]; call [eax + 0xc] > 0x10009352 : mov ebx, [eax]; call [ebx + 0x30] > 0x1000891f : mov edx, [ebx]; push ecx; push edx; call edi > 0x10001ad1 : mov ebp, [eax]; call [ebp + 0x50] > 0x10008a08 : mov eax, [esi + 0x40]; push eax; call edi > 0x10001c94 : mov ecx, [esi + 0x464]; push ecx; call edi > 0x10008ed7 : mov ebx, [ecx]; push ecx; call [ebx + 0x10] > 0x10001af0 : mov ebp, [ecx]; push ecx; call [ebp + 0x2c] > 0x10007fdc : mov ecx, [eax + 0x3c]; mov [edx + 0x3c], ecx; pop esi; ret 4 > 0x10003fe4 : mov ebp, [ebx]; push eax; push 0; push ebx; call [ebp + 0x64] > 0x10001c1f : mov eax, [edi]; push eax; mov ebp, [eax]; call [ebp + 8] > 0x10007fd9 : mov eax, [edx + 0x3c]; mov ecx, [eax + 0x3c]; mov [edx + 0x3c], ecx; pop esi; ret 4