No, it uses layer 2 communication at that point. On the 6 FreeBSD stations I have, you are apparently right. It looks like a way to exploit a system without access to the ports. I'm not sure why the kernel intercepts the data that way (you didn't even use a NOP sled.) -Josh