ropshell> use 911ddf2e16761643a47225f654d811e5 (download) name : ntdll.dll (i386/PE) base address : 0x7c901000 total gadgets: 6968
ropshell> suggest "load reg" > 0x7c90192c : pop ebx; ret > 0x7c96d53a : pop ecx; ret > 0x7c90137d : pop edx; ret > 0x7c901d52 : pop esi; ret > 0x7c902486 : pop edi; ret > 0x7c90e504 : pop ebp; ret > 0x7c905988 : popal ; ret 0 > 0x7c972c6a : pop eax; pop ebp; ret > 0x7c96961a : pop esp; pop ebp; ret 8 > 0x7c902488 : mov eax, [esp + 4]; ret > 0x7c90269b : mov ecx, [esp + 4]; sub eax, ecx; ret > 0x7c9031ae : mov edx, [esp + 4]; xor eax, eax; shl edx, cl; ret 0xc > 0x7c902c44 : mov edi, [esp + 8]; mov ecx, [esp + 0xc]; mov eax, [esp + 0x10]; shr ecx, 2; rep stosd es:[edi], eax; pop edi; ret 0xc