I wrote a quick and lame POC :P Well the other way is probably a ret-into-libc since you're not gonna be able to execute your shellcode, but I am too bored to write it now. (btw. the first challenge was better than this (even if it was already well documented aswell..)
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:39 EDT