← All OSCP Flashcard Decks

Buffer Overflow Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Buffer Overflow flashcards as text
  1. When a module shows 'Rebase: False, SafeSEH: False, ASLR: False, NXCompat: False' in Mona, what does this indicate for exploitation?

    Answer: The module's addresses are static and safe to use as JMP ESP targets

    All protections disabled means the module loads at a fixed base address every time, making its instruction addresses reliable for exploitation.

  2. During SEH-based buffer overflow exploitation, what two values must be overwritten in the SEH chain?

    Answer: nSEH (next SEH) and SEH handler address

    In SEH overwrites, nSEH is replaced with a short jump over itself and the handler pointer is replaced with a POP POP RET gadget address.

  3. What is the purpose of placing '\xeb\x06\x90\x90' in the nSEH position of an SEH buffer overflow exploit?

    Answer: It is a short forward jump that skips over the 4-byte SEH handler pointer

    \xeb\x06 is a 2-byte short JMP +6 that jumps past the 4-byte SEH handler overwrite, landing in the NOP sled before shellcode.

  4. In Windows x86 exploitation, a POP POP RET gadget is used in SEH overwrites because it accomplishes what?

    Answer: It removes two stack values then returns to the address stored in ESP, which points to nSEH

    POP POP RET adjusts ESP past the exception record pointers so that RET loads the nSEH address into EIP.

  5. Which msfvenom encoder is commonly used when 0x00, 0x0a, and 0x0d are bad characters and encoding is required?

    Answer: x86/shikata_ga_nai

    x86/shikata_ga_nai is a polymorphic XOR encoder that avoids null bytes and other common bad characters by default.

  6. After generating shellcode with msfvenom for a reverse shell, what local command must be running to catch the connection?

    Answer: A Metasploit multi/handler configured with matching payload and LHOST/LPORT

    A Metasploit multi/handler (or netcat for simple shells) must listen on the attacker's LHOST:LPORT matching the shellcode's compiled-in values.

  7. When testing badchars, you send \x01 through \xff in the payload. In the debugger's stack dump, \x0a is missing and \x0b appears as \x00. What can you conclude?

    Answer: Both 0x0a and 0x0b are bad characters

    A missing byte means it was stripped (bad), and a corrupted subsequent byte indicates the bad char caused corruption — both must be excluded.