Question 1
A penetration tester is evaluating a financial institution's internal network. They discover a legacy system running a custom application that is critical for back-office operations. The tester suspects the application is vulnerable to a buffer overflow but finds that Data Execution Prevention (DEP) is enabled on the host operating system. To bypass DEP, the tester plans to use a Return-Oriented Programming (ROP) attack. Which of the following is the primary goal of creating a ROP chain in this scenario?
Answer and explanation
Correct answer: B
Return-Oriented Programming (ROP) is an advanced exploitation technique used to bypass security measures like DEP. It works by finding small pieces of executable code, called 'gadgets,' within the existing codebase of a program and its loaded libraries. Each gadget typically performs a small operation (like loading a value into a register) and ends with a ret instruction. By carefully crafting a sequence of addresses on the stack, an attacker can chain these gadgets together to perform complex operations, such as calling VirtualProtect to mark a memory region as executable, thus bypassing DEP.