One Byte Frame Pointer Overwrite Hardcoded Exploits – This paper describes how to exploit overflows which are off by only one byte. Includes sample code.
You can download it from the following link: https://packetstormsecurity.com/files/download/31905/ebpoverflow.txt
Source: https://packetstormsecurity.com/files/31905/ebpoverflow.txt.html

