You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
Start practicing
Buffer Overflow Fundamentals — choose a session length
Free · No account required
Domain overview
This domain covers stack-based buffer overflow exploitation on 32-bit targets, as taught in PEN-200 and exercised in the OSCP lab and exam. You must recognize a crash, control EIP, find bad characters, locate a JMP ESP or equivalent return address, generate shellcode with msfvenom, and land a working reverse or bind shell on the target.
Exam objectives
Using a fuzzer or pattern_create/pattern_offset to find the exact EIP overwrite offset
Identifying bad characters by sending byte arrays and inspecting the debugger memory dump
Locating a JMP ESP or CALL ESP instruction with mona.py or Immunity Debugger
Generating and delivering msfvenom shellcode that spawns a reverse or bind shell
Assuming the offset from pattern_offset is correct without re-verifying EIP control with a unique four-byte value such as BBBB
Forgetting that null bytes and other bad characters will truncate shellcode, causing the payload to fail silently after EIP control
Placing shellcode before the saved return address when the buffer is too small, instead using a jump back into the buffer or a larger buffer region
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?
2Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?
3Which TWO of the following statements correctly describe the function of a NOP sled in a buffer overflow exploit?
4When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?
5Why must you carefully identify 'bad characters' before finalizing an exploit payload?
6Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?
7Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?
8Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?
9Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?
10What role does the 'padding' play in a buffer overflow payload structure?
11Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?
12What is the primary purpose of an exploit payload in a buffer overflow context?
13Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?
14When analyzing a stack buffer, what is the significance of the 'saved EBP' value?
15During a stack-based buffer overflow exploitation attempt in a Win32 environment, you notice that your shellcode execution fails because certain memory addresses contain null bytes (0x00). Which component of the exploit development process is primarily responsible for identifying and mitigating bad characters?
16While debugging a custom TCP server running on a Windows target, you send an overly long string of 'A' characters and notice that the application crashes, overwriting the EIP register with 0x41414141. What does this specific hex value indicate about the state of the debugger?
17You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?
18During a stack-based buffer overflow exploit development exercise against a custom Windows application, an OSCP student successfully overwrites the instruction pointer (EIP) with the address of a JMP ESP instruction. However, upon triggering the vulnerability, the application immediately crashes with an access violation before executing the shellcode located directly after the return address. Which of the following is the most likely root cause of this execution failure?
19During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?
20You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?
21You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?
22You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?
23You are developing an exploit for a 32-bit Windows application that contains a stack-based buffer overflow. After overwriting EIP with a JMP ESP address, you place a payload that includes a reverse shell. During testing, the shell connects back successfully, but the application crashes immediately after the shell terminates. What is the most likely cause of the crash?
24You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?
25You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?
26You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?
27During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?
28You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?
29During an exploit development exercise on a 32-bit Windows application, you have identified that a JMP ESP instruction resides at 0x625011AF inside a module that is not protected by ASLR or SafeSEH. You need to place your shellcode after the overwritten return address. What is the primary reason for using this JMP ESP address rather than jumping directly to a stack address where your shellcode resides?
30During a buffer overflow exploit development, you need to determine the exact number of bytes required to overwrite the EIP register. Which method is most commonly used to find this offset?
31You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?
32You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?
You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
The Courseiva PEN-200 question bank contains 32 questions in the Buffer Overflow Fundamentals domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Buffer Overflow Fundamentals domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included