ropshell> use 4329ee7d502c9113eba0f9570392f5ee (download) name : hal.dll (i386/PE) base address : 0x80010400 total gadgets: 963
ropshell> suggest "load reg" > 0x80010aae : pop eax; ret > 0x80010c05 : pop ebx; ret > 0x80014101 : pop esi; ret > 0x80018f4d : pop edi; ret 0xc > 0x8001399e : pop ebp; ret > 0x80011f70 : popal ; ret 4 > 0x80018b40 : mov edx, [esp + 0xc]; wrmsr ; ret 0xc > 0x800129c1 : pop edx; mov eax, 1; mov [ecx + 0x1c], dl; ret > 0x80017107 : pop esp; fiadd [ecx]; or [ebx + 0x5e5f1c45], 0xc9; ret 0x18 > 0x8001296c : pop ecx; mov [ecx + 0x1c], al; mov [ecx + 4], esp; ret > 0x80018b3c : mov eax, [esp + 8]; mov edx, [esp + 0xc]; wrmsr ; ret 0xc > 0x80018a7e : mov ecx, [esp + 0xc]; rep insb es:[edi], dx; mov edi, eax; ret 0xc > 0x80010baa : mov esi, [esp + 0x1c]; mov [esi], edx; pop esi; pop ebx; ret 0x14 > 0x80018a7a : mov edi, [esp + 8]; mov ecx, [esp + 0xc]; rep insb es:[edi], dx; mov edi, eax; ret 0xc