ropshell> use 68a1208ea67d35fe91b0af43baa53ad8 (download)
name         : stack4 (i386/RAW)
base address : 0x0
total gadgets: 10500
ropshell> suggest
call
    > 0x000008e3 : call eax
    > 0x00029d36 : call ebx
    > 0x000005ba : call ecx
    > 0x0000091d : call edx
    > 0x00026e97 : call esi
jmp
    > 0x0004bee1 : push esp; ret
    > 0x00008b44 : jmp eax
    > 0x00014fa4 : jmp ebx
    > 0x000141df : jmp ecx
    > 0x00055e4f : jmp edx
load mem
    > 0x0008a5e6 : mov edi, [edx]; ret
    > 0x00071320 : mov eax, [edx + 0x4c]; ret
    > 0x0000db6e : movzx eax, [edx]; pop ebx; pop esi; ret
    > 0x0005279f : mov eax, [esi]; pop ebx; pop esi; ret
    > 0x0000d7a9 : mov eax, [ecx]; mov [edx], eax; ret
load reg
    > 0x000713a6 : pop eax; ret
    > 0x000001d1 : pop ebx; ret
    > 0x00027daa : pop edx; ret
    > 0x00001964 : pop esi; ret
    > 0x00008a7d : pop edi; ret
pop pop ret
    > 0x000713a6 : pop eax; ret
    > 0x0005298c : pop ebx; pop edi; ret
    > 0x000566a5 : pop ebp; pop esi; pop edi; ret
    > 0x000562da : pop eax; pop ebx; pop esi; pop edi; ret
    > 0x00013a40 : pop esp; pop ebx; pop esi; pop edi; pop ebp; ret
sp lifting
    > 0x000628ec : add esp, 0x14; ret
    > 0x000628ec : add esp, 0x14; ret
    > 0x0000172a : add esp, 0x2c; ret
stack pivoting
    > 0x00000e65 : xchg eax, esp; ret
    > 0x000715d2 : mov esp, ecx; ret
    > 0x00000a49 : lea esp, [ecx - 4]; ret
    > 0x00002ff6 : lea esp, [ebp - 0xc]; pop ebx; pop esi; pop edi; pop ebp; ret
    > 0x000612ab : lea esp, [edx + edi*8 - 1]; call [edx + 0x52]
syscall
    > 0x00028370 : int 0x80; ret
write mem
    > 0x00058489 : add [ecx], eax; ret
    > 0x00006caf : add [ecx], edi; ret
    > 0x0008f2e6 : add [edx], ecx; ret
    > 0x0001fb81 : add [eax + 0x5f028d02], ecx; ret
    > 0x000258d4 : add [ebx + 0x5e5b04c4], eax; ret