ropshell> use 6d58daff3c7c496b236010345b9bc9d6 (download)
name         : think-twice (x86_64/ELF)
base address : 0x4004f0
total gadgets: 8882
ropshell> suggest
call
    > 0x00401287 : call rax
    > 0x0040094d : call rbx
    > 0x0041b628 : call rcx
    > 0x0040e9f7 : call rdx
    > 0x0044fa21 : call rsi
jmp
    > 0x004519d4 : push rsp; ret
    > 0x00400ab1 : jmp rax
    > 0x00489521 : jmp rbx
    > 0x004231c2 : jmp rcx
    > 0x0040d3a5 : jmp rdx
load mem
    > 0x004139d0 : movzx eax, [rdx]; ret
    > 0x004a88d1 : mov rax, [rsi + 0x10]; ret
    > 0x00419440 : mov rax, [rdi + 0x68]; ret
    > 0x00487b8c : mov eax, [rdx + 4]; ret
    > 0x004a88d2 : mov eax, [rsi + 0x10]; ret
load reg
    > 0x0044a71c : pop rax; ret
    > 0x00400ed8 : pop rbx; ret
    > 0x0044cd06 : pop rdx; ret
    > 0x00410933 : pop rsi; ret
    > 0x004006a6 : pop rdi; ret
pop pop ret
    > 0x0044cd05 : pop r10; ret
    > 0x0040dbd9 : pop r12; pop r13; ret
    > 0x0041092e : pop r12; pop r13; pop r14; ret
    > 0x0040069f : pop r12; pop r13; pop r14; pop r15; ret
    > 0x004026ee : pop r12; pop r13; pop r14; pop r15; pop rbp; ret
sp lifting
    > 0x0040dd1d : add rsp, 0x118; ret
    > 0x0040dd1d : add rsp, 0x118; ret
    > 0x0044a4e9 : add rsp, 0x28; ret
    > 0x0047ed70 : add rsp, 0x38; ret
    > 0x0044a719 : add rsp, 0x58; ret
stack pivoting
    > 0x004a7eb6 : mov rsp, rcx; ret
    > 0x004677c2 : xchg eax, esp; ret
    > 0x004a7eb7 : mov esp, ecx; ret
    > 0x0044b5e7 : mov esp, edx; call rbp
    > 0x0044bbc0 : mov esp, esi; call r15
syscall
    > 0x0047e285 : syscall ; ret
write mem
    > 0x00448098 : adc [rbx], eax; ret
    > 0x00444be1 : add [rax + 0x28d4802], ecx; ret
    > 0x00439796 : adc [rcx + 7], rdi; ret
    > 0x00439797 : adc [rcx + 7], edi; ret
    > 0x00447d1e : adc [rsi + 3], rdx; ret