PEN-200 · domain
Buffer Overflow Fundamentals
This domain covers stack-based buffer overflow exploitation on 32-bit targets, as taught in PEN-200 and exercised in the OSCP lab and exam. You must recognize a crash, control EIP, find bad characters, locate a JMP ESP or equivalent return address, generate shellcode with msfvenom, and land a working reverse or bind shell on the target.
Focused practice
Practice Buffer Overflow Fundamentals questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Buffer Overflow Fundamentals
You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
Using a fuzzer or pattern_create/pattern_offset to find the exact EIP overwrite offset
Identifying bad characters by sending byte arrays and inspecting the debugger memory dump
Locating a JMP ESP or CALL ESP instruction with mona.py or Immunity Debugger
Generating and delivering msfvenom shellcode that spawns a reverse or bind shell
Watch out for
Common Buffer Overflow Fundamentals exam traps
- ▸Assuming the offset from pattern_offset is correct without re-verifying EIP control with a unique four-byte value such as BBBB
- ▸Forgetting that null bytes and other bad characters will truncate shellcode, causing the payload to fail silently after EIP control
- ▸Placing shellcode before the saved return address when the buffer is too small, instead using a jump back into the buffer or a larger buffer region
Question index
All Buffer Overflow Fundamentals questions (32)
Click any question to see the full explanation, or start a practice session above.
Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?
Medium2You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?
Easy3You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?
Hard4You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?
Medium5During a stack-based buffer overflow exploitation attempt in a Win32 environment, you notice that your shellcode execution fails because certain memory addresses contain null bytes (0x00). Which component of the exploit development process is primarily responsible for identifying and mitigating bad characters?
Medium6Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?
Medium7Which TWO of the following statements correctly describe the function of a NOP sled in a buffer overflow exploit?
Hard8You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?
Hard9Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?
Hard10You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?
Hard11During a buffer overflow exploit development, you need to determine the exact number of bytes required to overwrite the EIP register. Which method is most commonly used to find this offset?
Easy12Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?
Medium13While debugging a custom TCP server running on a Windows target, you send an overly long string of 'A' characters and notice that the application crashes, overwriting the EIP register with 0x41414141. What does this specific hex value indicate about the state of the debugger?
Easy14You are developing an exploit for a 32-bit Windows application that contains a stack-based buffer overflow. After overwriting EIP with a JMP ESP address, you place a payload that includes a reverse shell. During testing, the shell connects back successfully, but the application crashes immediately after the shell terminates. What is the most likely cause of the crash?
Medium15What role does the 'padding' play in a buffer overflow payload structure?
Medium16You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?
Medium17You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?
Medium18During a stack-based buffer overflow exploit development exercise against a custom Windows application, an OSCP student successfully overwrites the instruction pointer (EIP) with the address of a JMP ESP instruction. However, upon triggering the vulnerability, the application immediately crashes with an access violation before executing the shellcode located directly after the return address. Which of the following is the most likely root cause of this execution failure?
Medium19During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?
Hard20Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?
Medium21You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?
Easy22During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?
Medium23What is the primary purpose of an exploit payload in a buffer overflow context?
Easy24You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?
Medium25When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?
Easy26You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?
Medium27Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?
Medium28During an exploit development exercise on a 32-bit Windows application, you have identified that a JMP ESP instruction resides at 0x625011AF inside a module that is not protected by ASLR or SafeSEH. You need to place your shellcode after the overwritten return address. What is the primary reason for using this JMP ESP address rather than jumping directly to a stack address where your shellcode resides?
Medium29Why must you carefully identify 'bad characters' before finalizing an exploit payload?
Hard30Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?
Easy31You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?
Medium32When analyzing a stack buffer, what is the significance of the 'saved EBP' value?
EasyOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Buffer Overflow Fundamentals domain cover on the PEN-200 exam?
- You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
- How many questions are in this domain?
- This page lists all 32 Buffer Overflow Fundamentals questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Buffer Overflow Fundamentals questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.