Hi,

I see that there are many products (chat clients, browsers, what not?) are prone to buffer overflow attacks.

I also see that some hacker finds the buffer overflow vulnerability and publishes a program to programatically do that.

Now, my question is how do hackers detect such buffer overflow vulnerabilities ?

Thanks,
Rich.