THM Buffer Overflow Prep - grunt92/IT-Sec-WriteUps GitHub Wiki

Deploy VM

Deploy the VM and login using RDP.

For all tasks in this room all necessary steps are provided by THM. Therefore I will only write down the requested answers. No answer needed

oscp.exe-OVERFLOW1

What is the EIP offset for OVERFLOW1?

1978

In byte order (e.g. \x00\x01\x02) and including the null byte \x00, what were the badchars for OVERFLOW1?

\x00\x07\x2e\xa0

oscp.exe-OVERFLOW2

What is the EIP offset for OVERFLOW2?

634

In byte order (e.g. \x00\x01\x02) and including the null byte \x00, what were the badchars for OVERFLOW2?

\x00\x23\x3c\x83\xba