โ† All OSCP Flashcard Decks

Buffer Overflow Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Buffer Overflow flashcards as text
  1. What does ASLR (Address Space Layout Randomization) do that complicates standard buffer overflow exploitation?

    Answer: It randomizes base addresses of the stack, heap, and libraries each run, making hardcoded addresses unreliable

    ASLR randomizes memory layout on each execution, so a hardcoded JMP ESP or shellcode address will be invalid on the next run.

  2. A stack canary (stack cookie) mitigation places a random value before the saved return address. What exploitation technique can defeat it without leaking the canary?

    Answer: Using a heap overflow to corrupt a function pointer instead of the stack return address

    Targeting heap-based function pointers or other non-stack control flow bypasses the stack canary entirely since the canary check only guards the stack.

  3. In a DEP (Data Execution Prevention) environment, why does placing shellcode on the stack and jumping to it fail?

    Answer: DEP marks the stack memory page as non-executable, causing a fault when ESP-resident code is executed

    DEP enforces a W^X (write XOR execute) policy: pages that are writable (like the stack) are marked non-executable, so code injected there faults.

  4. Return-Oriented Programming (ROP) is used to bypass DEP. What are ROP gadgets?

    Answer: Short sequences of existing executable instructions ending in a RET, chained via the stack

    ROP chains existing code (gadgets: instruction sequences ending in RET) already marked executable to perform arbitrary operations without injecting new code.

  5. During OSCP buffer overflow labs, the 'spike' tool is used. What is its primary function?

    Answer: It performs protocol fuzzing by sending malformed data to network services

    SPIKE is a fuzzing framework that sends progressively mutated protocol-aware input to network services to identify crash-inducing inputs.

  6. You are exploiting a buffer overflow and your reverse shell payload is 400 bytes. The buffer space after EIP is only 300 bytes. What is the best solution?

    Answer: Jump backward to earlier buffer space or use a first-stage egghunter payload

    When available space after EIP is too small, a short egghunter (about 32 bytes) or a backward JMP to earlier buffer space where the full shellcode fits is the standard solution.

  7. What is an egghunter shellcode and when is it used in buffer overflow exploitation?

    Answer: A small stub (~32 bytes) that searches process memory for a 8-byte tag preceding the real shellcode

    An egghunter is a tiny payload that scans memory for a unique 4-byte tag repeated twice, then jumps to the full shellcode placed elsewhere in memory.