PEN-200 Buffer Overflow Fundamentals Practice Question
You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?
⚠ Common exam trap
The trap here is assuming that encoding shellcode will fix corruption caused by bad characters, when the encoder itself may produce bytes that the vulnerable function rejects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send a byte array from 0x00 to 0xFF and inspect the stack in a debugger to see which bytes are truncated or altered.
Sending the full 0x00-0xFF byte range and inspecting stack memory in a debugger is the definitive way to identify bad characters. It shows which bytes are truncated or transformed by the vulnerable function. Static analysis and encoding do not replace this dynamic test. This step must precede shellcode generation to ensure payload integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a strings command on the vulnerable binary to list all characters that appear in the code.
Why it's wrong here
strings lists printable sequences in a binary but does not indicate which bytes the program filters or mishandles at runtime. Bad characters depend on how functions like strcpy, scanf, or network parsing treat specific byte values. Static inspection cannot replace dynamic testing, where you observe actual memory contents after sending a crafted buffer.
- ✓
Send a byte array from 0x00 to 0xFF and inspect the stack in a debugger to see which bytes are truncated or altered.
Why this is correct
Sending the full byte range and examining memory after the crash reveals exactly which bytes are removed, terminated, or transformed by the vulnerable function. For example, a null byte may truncate a string copy, and a newline may terminate input. This empirical approach is the standard method taught in PEN-200 for mapping bad characters before finalizing shellcode.
- ✗
Encode your shellcode with shikata_ga_nai and assume any remaining corruption is due to the encoder.
Why it's wrong here
Encoding shellcode does not eliminate bad characters; the encoder's output may still contain bytes that the vulnerable function rejects. In fact, encoders often introduce null bytes or other problematic values. You must first identify bad characters empirically and then choose or customize an encoder that avoids them. Assuming the encoder is at fault without testing is guesswork.
- ✗
Use a disassembler to check whether the binary contains any null bytes in its machine code.
Why it's wrong here
Null bytes in the binary's own machine code are unrelated to which bytes your input can contain. The relevant question is how the vulnerable function processes your supplied data, not what instructions the compiler emitted. Disassembly may reveal calls to dangerous functions, but it does not enumerate runtime bad characters; dynamic testing is required.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.