Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?
Security systems often scan for known shellcode patterns or restricted characters like null bytes (0x00). Encoding the payload allows it to pass through these filters by obfuscating the malicious bytes into a benign-looking format, which is later decoded by a small stub upon reaching memory.
Why this answer
Encoding is used to transform shellcode to bypass security filters, such as Intrusion Detection Systems (IDS) or character filtering (like null bytes). By changing the signature of the payload, it avoids triggering pattern-based detection. This is a fundamental technique for ensuring the payload reaches its intended execution point without being sanitized or blocked by input validation controls that inspect data for known malicious sequences.
Exam trap
Candidates frequently confuse shellcode encoding with encryption, assuming it provides confidentiality against analysts rather than modifying bytes to bypass character filters.