ropshell> use fadb3e5e0f0200befcf977d0cccdf983 (download) name : pwn (x86_64/ELF) base address : 0x400390 total gadgets: 8930
ropshell> suggest "stack pivoting" > 0x004a636d : mov rsp, rcx; ret > 0x004018eb : xchg eax, esp; ret > 0x004a636e : mov esp, ecx; ret > 0x0047515c : lea rsp, [rbp - 0x10]; pop rbx; pop r12; pop rbp; ret > 0x00422924 : xchg edi, esp; add al, 0; add dh, dh; ret > 0x0047515d : lea esp, [rbp - 0x10]; pop rbx; pop r12; pop rbp; ret > 0x004826a9 : mov rsp, r8; mov rbp, r9; nop ; jmp rdx > 0x004826aa : mov esp, eax; mov rbp, r9; nop ; jmp rdx > 0x00449b84 : mov esp, edx; mov rbp, rax; call rax > 0x00418bbd : mov rsp, rbx; lea rsp, [rbp - 0x18]; pop rbx; pop r12; pop r13; pop rbp; ret > 0x00418bbe : mov esp, ebx; lea rsp, [rbp - 0x18]; pop rbx; pop r12; pop r13; pop rbp; ret > 0x004599eb : lea esp, [rsi + rax]; mov rbx, rax; mov rdi, r12; call r15 > 0x0045c2a0 : movsxd rsp, edx; mov rdx, r12; mov rax, [rdi + 0xd8]; call [rax + 0x38] > 0x0041efa4 : mov esp, esi; push rbx; mov rax, [rdi + 0xd8]; mov rbx, rdi; mov rbp, rdx; call [rax + 0x60] > 0x00400c6c : leave ; ret