ropshell> use 5daeefc2258079d21b4d865e88939d50 (download) name : libc.so.6 (x86_64/ELF) base address : 0x25340 total gadgets: 17467
ropshell> suggest "stack pivoting" > 0x00041466 : xchg eax, esp; ret > 0x0007edf4 : mov esp, eax; mov rax, r12; pop r12; ret > 0x0003b4a8 : mov rsp, r8; mov rbp, r9; jmp rdx > 0x000c946b : lea rsp, [rbp - 0x10]; pop r12; pop r13; pop rbp; ret > 0x000c946c : lea esp, [rbp - 0x10]; pop r12; pop r13; pop rbp; ret > 0x0007ee01 : mov esp, ebp; pop rbx; pop rbp; mov rax, r12; pop r12; ret > 0x00066b8c : movsxd rsp, esp; mov rdx, r12; call [r13 + 0x38] > 0x0003ca64 : lea esp, [rcx + rax]; mov rdi, r12; call rbx > 0x001234bd : mov esp, esp; lea rsi, [rsp + 8]; call [rax] > 0x0003df29 : lea esp, [rbx + rax*8 + 8]; nop [rax]; call [rbx] > 0x001206ed : push rdi; pop rsp; lea rsi, [rdi + 0x48]; mov rdi, r8; mov rax, [rax + 0x18]; jmp rax > 0x00122f1c : lea esp, [rax + 0x23b0]; xor esi, esi; mov [rax + 0x23b0], 1; mov rax, [rax + 0x23b8]; mov rdi, r12; call [rax + 0x28] > 0x0004cef0 : leave ; ret