6. Finding Bad Characters
Generate a bytearray using mona, and exclude the null byte (\x00) by default. Note the location of the bytearray.bin file that is generated.
Now generate a string of bad chars that is identical to the bytearray. The following python script can be used to generate a string of bad chars from \x01 to \xff:
Put the string of bad chars before the C's in your buffer, and adjust the number of C's to compensate:
Crash the application using this buffer, and make a note of the address to which ESP points. This can change every time you crash the application, so get into the habit of copying it from the register each time.
Use the mona compare command to reference the bytearray you generated, and the address to which ESP points:
Last updated