Local exploit for BulletProof FTP Client 2010 - Buffer Overflow (SEH) Exploit, this exploit store 2nd shellcode on heap and use egghunter to locate and copy 2nd shellcode back to stack before executing the shellcode.
https://gist.github.com/mfadzilr/c8980087db10c47bdfb6