← All OSCP Flashcard Decks

Buffer Overflow Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Buffer Overflow flashcards as text
  1. During a Windows x86 buffer overflow, after overwriting EIP, what is the typical next step to redirect execution to your shellcode?

    Answer: Find a JMP ESP gadget in a non-ASLR module

    A JMP ESP instruction in a module without ASLR redirects execution to the top of the stack where shellcode resides.

  2. What does the 'badchars' identification step accomplish in a buffer overflow exploit?

    Answer: It finds characters that corrupt or truncate shellcode in memory

    Bad characters are bytes that get modified, dropped, or cause early string termination, which would break shellcode execution.

  3. In Immunity Debugger, what is the purpose of the Mona plugin command '!mona jmp -r esp'?

    Answer: It searches all loaded modules for JMP ESP instructions

    '!mona jmp -r esp' finds all JMP ESP (or equivalent) instructions across loaded modules for use as an EIP redirect.

  4. When using msfvenom to generate shellcode for a Windows buffer overflow, which flag specifies characters to exclude from the payload?

    Answer: -b

    The -b flag in msfvenom specifies bad characters to exclude from the generated shellcode.

  5. Why are NOP sleds (\x90 instructions) typically prepended before shellcode in a buffer overflow payload?

    Answer: They provide a landing zone that tolerates slight ESP offset variations

    A NOP sled gives the exploit tolerance for minor address variations — the CPU slides through NOPs until reaching the shellcode.

  6. A fuzzer sends increasingly large strings to a vulnerable service and it crashes when the buffer is 1100 bytes. What is the correct next step?

    Answer: Send a cyclic pattern of 1100 bytes to find the exact EIP offset

    After identifying the crash size, a unique cyclic pattern (e.g., from msf-pattern_create) of that length is sent to determine the exact EIP offset.

  7. Which register is typically inspected after a crash to find the EIP offset when using a Metasploit cyclic pattern?

    Answer: EIP

    EIP contains the 4-byte value from the cyclic pattern at crash time, which msf-pattern_offset uses to calculate the exact offset.