Before you overwrite a return address, you have to know exactly where it lives.
Binary exploitation rewards people who can point to a specific byte and say why it matters. Not "the buffer overflows" but "this write goes eight bytes past the buffer, over the saved RBP, into the return address" — and until you can say that, the stack is just a diagram, not a target.
your tutor starts by putting an actual stack frame in front of you: locals, saved RBP, return address, stacked in the order a function call actually pushes them. You work out the offset by hand, with a cyclic pattern and a debugger, before anyone talks about ROP or canaries or bypassing anything. The mitigations only make sense once you've felt the plain overflow work — and then hit the wall each one puts up.
This isn't a substitute for your coursework or your CTF team's writeups. It's where you stop pasting exploit scripts you don't understand and start predicting, before you run a payload, exactly where the crash will land and why.
Start exploring Binary Exploitation tonight — a 30-day trial, cancel anytime.
Start your 30-day trial