Courseiva

PEN-200 · domain

Buffer Overflow Fundamentals

This domain covers stack-based buffer overflow exploitation on 32-bit targets, as taught in PEN-200 and exercised in the OSCP lab and exam. You must recognize a crash, control EIP, find bad characters, locate a JMP ESP or equivalent return address, generate shellcode with msfvenom, and land a working reverse or bind shell on the target.

32 questions8 easy17 medium7 hard

Focused practice

Practice Buffer Overflow Fundamentals questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Buffer Overflow Fundamentals

You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.

Using a fuzzer or pattern_create/pattern_offset to find the exact EIP overwrite offset

Identifying bad characters by sending byte arrays and inspecting the debugger memory dump

Locating a JMP ESP or CALL ESP instruction with mona.py or Immunity Debugger

Generating and delivering msfvenom shellcode that spawns a reverse or bind shell

Watch out for

Common Buffer Overflow Fundamentals exam traps

  • ▸Assuming the offset from pattern_offset is correct without re-verifying EIP control with a unique four-byte value such as BBBB
  • ▸Forgetting that null bytes and other bad characters will truncate shellcode, causing the payload to fail silently after EIP control
  • ▸Placing shellcode before the saved return address when the buffer is too small, instead using a jump back into the buffer or a larger buffer region

Question index

All Buffer Overflow Fundamentals questions (32)

Click any question to see the full explanation, or start a practice session above.

1

Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?

Medium
2

You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?

Easy
3

You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?

Hard
4

You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?

Medium
5

During a stack-based buffer overflow exploitation attempt in a Win32 environment, you notice that your shellcode execution fails because certain memory addresses contain null bytes (0x00). Which component of the exploit development process is primarily responsible for identifying and mitigating bad characters?

Medium
6

Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?

Medium
7

Which TWO of the following statements correctly describe the function of a NOP sled in a buffer overflow exploit?

Hard
8

You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?

Hard
9

Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?

Hard
10

You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?

Hard
11

During a buffer overflow exploit development, you need to determine the exact number of bytes required to overwrite the EIP register. Which method is most commonly used to find this offset?

Easy
12

Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?

Medium
13

While debugging a custom TCP server running on a Windows target, you send an overly long string of 'A' characters and notice that the application crashes, overwriting the EIP register with 0x41414141. What does this specific hex value indicate about the state of the debugger?

Easy
14

You are developing an exploit for a 32-bit Windows application that contains a stack-based buffer overflow. After overwriting EIP with a JMP ESP address, you place a payload that includes a reverse shell. During testing, the shell connects back successfully, but the application crashes immediately after the shell terminates. What is the most likely cause of the crash?

Medium
15

What role does the 'padding' play in a buffer overflow payload structure?

Medium
16

You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?

Medium
17

You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?

Medium
18

During a stack-based buffer overflow exploit development exercise against a custom Windows application, an OSCP student successfully overwrites the instruction pointer (EIP) with the address of a JMP ESP instruction. However, upon triggering the vulnerability, the application immediately crashes with an access violation before executing the shellcode located directly after the return address. Which of the following is the most likely root cause of this execution failure?

Medium
19

During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?

Hard
20

Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?

Medium
21

You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?

Easy
22

During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?

Medium
23

What is the primary purpose of an exploit payload in a buffer overflow context?

Easy
24

You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?

Medium
25

When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?

Easy
26

You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?

Medium
27

Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?

Medium
28

During an exploit development exercise on a 32-bit Windows application, you have identified that a JMP ESP instruction resides at 0x625011AF inside a module that is not protected by ASLR or SafeSEH. You need to place your shellcode after the overwritten return address. What is the primary reason for using this JMP ESP address rather than jumping directly to a stack address where your shellcode resides?

Medium
29

Why must you carefully identify 'bad characters' before finalizing an exploit payload?

Hard
30

Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?

Easy
31

You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?

Medium
32

When analyzing a stack buffer, what is the significance of the 'saved EBP' value?

Easy

Frequently asked questions

What does the Buffer Overflow Fundamentals domain cover on the PEN-200 exam?
You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
How many questions are in this domain?
This page lists all 32 Buffer Overflow Fundamentals questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Buffer Overflow Fundamentals questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
offsec-oscp OFFSEC-OSCP buffer overflow fundamentals Practice Questions