ropshell> use c2b9e53abad8cdf3822b7e428f4cc673 (download) name : libc.so.6 (x86_64/ELF) base address : 0x21a10 total gadgets: 14420
ropshell> suggest "stack pivoting" > 0x0004d3c0 : mov rsp, rdx; ret > 0x0003289f : xchg eax, esp; ret > 0x0004d3c1 : mov esp, edx; ret > 0x000c7650 : lea rsp, [rbp - 0x10]; pop rbx; pop r12; pop rbp; ret > 0x000c7651 : lea esp, [rbp - 0x10]; pop rbx; pop r12; pop rbp; ret > 0x00037557 : mov rsp, r8; mov rbp, r9; nop ; jmp rdx > 0x0004b5c5 : xchg esp, eax; idiv edi; jmp [rsi + 0xf] > 0x00042f2d : xchg esp, ecx; idiv edi; jmp [rsi + 0xf] > 0x00037558 : mov esp, eax; mov rbp, r9; nop ; jmp rdx > 0x00127bcd : mov esp, esp; call [rax + 0x18] > 0x00038ba4 : lea esp, [rdi + rax]; mov rdi, r12; call rbx > 0x0005c483 : mov esp, edi; sar r12, 2; mov rdx, r12; call [rax + 0x38] > 0x0003a071 : lea esp, [rbx + rax*8 + 8]; nop [rax]; call [rbx] > 0x001215c1 : push rdi; pop rsp; lea rsi, [rdi + 0x48]; mov rdi, rax; mov rcx, [rcx + 0x18]; jmp rcx > 0x0012a6f6 : lea esp, [rax - 1]; mov rax, [rbx + 0x70]; mov [rbx + 0x48], r12d; bswap r12d; call [rax + 0x18] > 0x000499dc : leave ; ret