Using the pattern_offset tool

Let's find the offset to the address of the next SEH frame and the offset to the address of the catch block, as follows:

We can see that the 4 bytes containing the memory address to the next SEH record starts from 4061 bytes and the offset to the catch block begins right after those 4 bytes; that is, from 4065.

Get Mastering Metasploit - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.