> For the complete documentation index, see [llms.txt](https://d4rk1337.gitbook.io/the-pentesters-cheat-sheet/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://d4rk1337.gitbook.io/the-pentesters-cheat-sheet/exploitation/buffer-overflow/01-general.md).

# General

> In information security and programming, a buffer overflow, or buffer overrun, is an anomaly where a program, while writing data to a buffer, overruns the buffer's boundary and overwrites adjacent memory locations.
>
> \-- [*Wikipedia*](https://en.wikipedia.org/wiki/Buffer_overflow)

## Related

* [Linux: Buffer overflow](/the-pentesters-cheat-sheet/exploitation/buffer-overflow/02-linux.md)
* [Windows: Buffer overflow](/the-pentesters-cheat-sheet/exploitation/buffer-overflow/03-windows.md)

## Protections

* Data Execution Prevention (DEP)
* Address Space Layout Randomization (ASLR)

## Important registers

* ESP (Extended Stack Pointer): top of stack
* EIP (Extended Instruction Pointer): current instruction\
  -> Override EIP with user input (e.g. strcpy)
