# One Gadget {% hint style="success" %} Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
Support HackTricks * Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! * **Join the** πŸ’¬ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.** * **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
{% endhint %} ## Basic Information [**One Gadget**](https://github.com/david942j/one\_gadget) дозволяє ΠΎΡ‚Ρ€ΠΈΠΌΠ°Ρ‚ΠΈ ΠΎΠ±ΠΎΠ»ΠΎΠ½ΠΊΡƒ Π·Π°ΠΌΡ–ΡΡ‚ΡŒ використання **system** Ρ‚Π° **"/bin/sh". One Gadget** Π·Π½Π°ΠΉΠ΄Π΅ Π² Π±Ρ–Π±Π»Ρ–ΠΎΡ‚Π΅Ρ†Ρ– libc спосіб ΠΎΡ‚Ρ€ΠΈΠΌΠ°Ρ‚ΠΈ ΠΎΠ±ΠΎΠ»ΠΎΠ½ΠΊΡƒ (`execve("/bin/sh")`), Π²ΠΈΠΊΠΎΡ€ΠΈΡΡ‚ΠΎΠ²ΡƒΡŽΡ‡ΠΈ лишС ΠΎΠ΄Π½Ρƒ **адрСсу**.\ Однак, Π·Π°Π·Π²ΠΈΡ‡Π°ΠΉ Ρ” дСякі обмСТСння, Π½Π°ΠΉΠΏΠΎΡˆΠΈΡ€Π΅Π½Ρ–ΡˆΡ– Ρ‚Π° Π»Π΅Π³ΠΊΡ– для уникнСння Ρ‚Π°ΠΊΡ–, як `[rsp+0x30] == NULL`. ΠžΡΠΊΡ–Π»ΡŒΠΊΠΈ Π²ΠΈ ΠΊΠΎΠ½Ρ‚Ρ€ΠΎΠ»ΡŽΡ”Ρ‚Π΅ значСння всСрСдині **RSP**, Π²Π°ΠΌ просто ΠΏΠΎΡ‚Ρ€Ρ–Π±Π½ΠΎ надіслати Ρ‰Π΅ ΠΊΡ–Π»ΡŒΠΊΠ° Π·Π½Π°Ρ‡Π΅Π½ΡŒ NULL, Ρ‰ΠΎΠ± ΡƒΠ½ΠΈΠΊΠ½ΡƒΡ‚ΠΈ обмСТСння. ![](<../../.gitbook/assets/image (615).png>) ```python ONE_GADGET = libc.address + 0x4526a rop2 = base + p64(ONE_GADGET) + "\x00"*100 ``` Π”ΠΎ адрСси, Π²ΠΊΠ°Π·Π°Π½ΠΎΡ— One Gadget, ΠΏΠΎΡ‚Ρ€Ρ–Π±Π½ΠΎ **Π΄ΠΎΠ΄Π°Ρ‚ΠΈ Π±Π°Π·ΠΎΠ²Ρƒ адрСсу, Π΄Π΅ Π·Π°Π²Π°Π½Ρ‚Π°ΠΆΠ΅Π½ΠΎ `libc`**. {% hint style="success" %} One Gadget Ρ” **Ρ‡ΡƒΠ΄ΠΎΠ²ΠΎΡŽ допомогою для Ρ‚Π΅Ρ…Π½Ρ–ΠΊ Arbitrary Write 2 Exec** Ρ– ΠΌΠΎΠΆΠ΅ **спростити ROP Π»Π°Π½Ρ†ΡŽΠ³ΠΈ**, ΠΎΡΠΊΡ–Π»ΡŒΠΊΠΈ Π²Π°ΠΌ ΠΏΠΎΡ‚Ρ€Ρ–Π±Π½ΠΎ лишС Π²ΠΈΠΊΠ»ΠΈΠΊΠ°Ρ‚ΠΈ ΠΎΠ΄Π½Ρƒ адрСсу (Ρ– Π²ΠΈΠΊΠΎΠ½Π°Ρ‚ΠΈ Π²ΠΈΠΌΠΎΠ³ΠΈ). {% endhint %} {% hint style="success" %} Π’ΠΈΠ²Ρ‡Π°ΠΉΡ‚Π΅ Ρ‚Π° ΠΏΡ€Π°ΠΊΡ‚ΠΈΠΊΡƒΠΉΡ‚Π΅ AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ Π’ΠΈΠ²Ρ‡Π°ΠΉΡ‚Π΅ Ρ‚Π° ΠΏΡ€Π°ΠΊΡ‚ΠΈΠΊΡƒΠΉΡ‚Π΅ GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
ΠŸΡ–Π΄Ρ‚Ρ€ΠΈΠΌΠ°Ρ‚ΠΈ HackTricks * ΠŸΠ΅Ρ€Π΅Π²Ρ–Ρ€Ρ‚Π΅ [**ΠΏΠ»Π°Π½ΠΈ підписки**](https://github.com/sponsors/carlospolop)! * **ΠŸΡ€ΠΈΡ”Π΄Π½ΡƒΠΉΡ‚Π΅ΡΡŒ Π΄ΠΎ** πŸ’¬ [**Π³Ρ€ΡƒΠΏΠΈ Discord**](https://discord.gg/hRep4RUj7f) Π°Π±ΠΎ [**Π³Ρ€ΡƒΠΏΠΈ Telegram**](https://t.me/peass) Π°Π±ΠΎ **слідкуйтС** Π·Π° Π½Π°ΠΌΠΈ Π² **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.** * **Π”Ρ–Π»Ρ–Ρ‚ΡŒΡΡ Ρ…Π°ΠΊΠ΅Ρ€ΡΡŒΠΊΠΈΠΌΠΈ Ρ‚Ρ€ΡŽΠΊΠ°ΠΌΠΈ, Π½Π°Π΄ΡΠΈΠ»Π°ΡŽΡ‡ΠΈ PR Π΄ΠΎ** [**HackTricks**](https://github.com/carlospolop/hacktricks) Ρ‚Π° [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) Ρ€Π΅ΠΏΠΎΠ·ΠΈΡ‚ΠΎΡ€Ρ–Ρ—Π² Π½Π° github.
{% endhint %}