ROP Primer: 0.2

  • Name: ROP Primer: 0.2
  • Date release: 13 Jun 2015

Please remember that VulnHub is a free community resource so we are unable to check the machines that are provided to us. Before you download, please read our FAQs sections dealing with the dangers of running unknown VMs and our suggestions for "protecting yourself and your network. If you understand the risks, please download!


(Size: 598 MB)

Our resident ROP ninja barrebas recently gave the team a bootcamp on Return Oriented Programming. The presentation was followed by a demo walkthrough on writing a ROP exploit on a vulnerable application. Since the presentation was well received, he’s decided to make the slides available to everyone. You can view them at

We hope you enjoy it!

Username: root
Password: toor

Username: level0
Password: warmup

ROP Primer

This VM is meant as a small introduction to 32-bit return-oriented-programming on Linux. It contains three vulnerable binaries, that must be exploited using ROP.

The machine is built and tested in VirtualBox 4.3.20. It's an Ubuntu 32 bit VM, with ASLR disabled. Useful tools like gdb-peda are installed. A description of the levels, including instructions, can be found on the webserver.

A big shout-out to my team mates of the Vulnhub CTF Team!

@barrebas, March 2015 & June 2015

MD5:  840c75497f54578497a6e44df2f96047
SHA1: 2cb14d78fd1ff7b5a7895447969fde8ca9c06ef3

Exclusive to VulnHub! **Release dates:** v0.1 = 04/03/2015 v0.2 = 13/06/2015 _Don't forget to check the web server for more information!_

  • Filename: rop-primer-v0.2.ova
  • File size: 598 MB
  • MD5: 840C75497F54578497A6E44DF2F96047
  • SHA1: 2CB14D78FD1FF7B5A7895447969FDE8CA9C06EF3

  • Format: Virtual Machine (Virtualbox - OVA)
  • Operating System: Linux

  • DHCP service: Enabled
  • IP address: Automatically assign