Writing a Simple Buffer Overflow Exploit @LiveOverflow
Writing a Simple Buffer Overflow Exploit  @LiveOverflow
Uploaded December 2019 | Updated September 2026, 2 weeks ago
Feel free to follow along! This walkthrough combines a format-string stack leak with a simple buffer overflow, uses the leaked buffer address to defeat ASLR, and builds a Python socket exploit that executes shellcode.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-format-string/format-string-ctf-challenges
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Sources and solution: gist.github.com/LiveOverflow/5fa36bec51968de696b11d3548b02148

CHAPTERS
00:00 - Compiling and serving the vulnerable challenge
01:20 - Combining a format-string leak with a buffer overflow
03:18 - Starting the Python socket exploit
03:38 - Identifying the leaked stack address in context
07:19 - Calculating the buffer start from the leak
08:48 - Receiving and parsing the leaked address reliably
10:34 - Finding the buffer-overflow offset
12:11 - Building the return-address and shellcode payload
13:30 - Pausing the exploit to attach GDB
14:42 - Packing the address and verifying control with INT3
16:14 - Replacing the test bytes with /bin/sh shellcode
17:27 - Moving shellcode before the return address
19:07 - Reproducing the shellcode-corruption pitfall

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#BufferOverflow #BinaryExploitation #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Writing a Simple Buffer Overflow ExploitResearching MissingNo Glitch in PokemonCannot access memory at address // Debugging PIE Binaries affected by ASLR - bin 0x2EDid an AI Really Hack Hugging Face?Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022Public Penetration Test Reports - Learning ResourceMinecraft Reach HackKernel Root Exploit via a ptrace() and execve() Race ConditionExploit Fails? Debug Your Shellcode - bin 0x2BDeepdive Containers - Kernel Sources and nsenterPentesting vs. Bug Bounty vs. Pentesting ???Solving Nintendo HireMe!!! with Basic Math
LiveOverflow |

Writing a Simple Buffer Overflow Exploit

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER