I actually have a 100% reliable solution that exploits the executable stack on level 04. No need to guess the address of the stack using one side effect that I found in this specific case:
https://gist.github.com/807e81ad64c4e84a7770 (SPOILERS)
https://gist.github.com/807e81ad64c4e84a7770 (SPOILERS)