One gadget
Quick win
A one gadget
is an execve("/bin/sh")
command that is directly present in gLIBC. Using this gadget it's possible to execute an arbitrary code with a single gadget.
Finding one gadget
It's possible to retrieve all one gadget of a libc using the tool one_gadget :
For most of one gadget
some requirements have to be met in order to execute the gadget.
Last updated