ropshell> use badbfe4ed1e3e040f2721ae400b92571 (download)
name         : exp5 (i386/ELF)
base address : 0x4c0
total gadgets: 46
ropshell> suggest
call
    > 0x0000053f : call eax
    > 0x0000058d : call edx
    > 0x000004e2 : call [eax + 0x51]
jmp
    > 0x000004f0 : push esp; mov ebx, [esp]; ret
load reg
    > 0x0000077b : pop ebp; ret
    > 0x0000077a : pop edi; pop ebp; ret
    > 0x00000719 : popal ; cld ; ret
    > 0x00000779 : pop esi; pop edi; pop ebp; ret
    > 0x000004f2 : mov ebx, [esp]; ret
pop pop ret
    > 0x0000077b : pop ebp; ret
    > 0x0000077a : pop edi; pop ebp; ret
    > 0x00000779 : pop esi; pop edi; pop ebp; ret
    > 0x00000778 : pop ebx; pop esi; pop edi; pop ebp; ret
stack pivoting
    > 0x00000718 : lea esp, [ecx - 4]; ret
    > 0x00000712 : lea esp, [ebp - 8]; pop ecx; pop ebx; pop ebp; lea esp, [ecx - 4]; ret
    > 0x00000595 : leave ; ret