Format string vulnerabilities in programs can be found by:
Forcing buffer overflows
Submitting random long strings to the application
Causing underflow problems
Including string specifiers in input data