jm33_ng
  • Malware
  • Misc
  • Programming
  • R&d
  • Tools
  • Vulnerabilities
  • RSS

jm33_ng


cyber security / noob developer / poor English

Some Notes on Call Stack Spoofing

Date Fri 21 August 2026 Tags windows / malware / stack spoofing / silentmoonwalk / emp3r0r / c2 / EDR

spoofed call stack

The Basics

Forgive me if this post sounds too basic or detailed. My tutor job gave me this style. Hopefully it helps beginners.

The screenshots are taken from different runs as I didn't have the time to finish writing in one go. If you see different addresses, that's why.

What …

View comments.

more ...

Writing a Linux BOF Loader from Scratch

Date Sat 17 January 2026 Tags linux-bof / linux / elf / in-memory / emp3r0r / mmap / bof / cobalt strike / c2

banner

Introduction

Beacon Object Files (BOFs) changed how we run code in memory on Windows. It is a nice workflow: an operator compiles a small C file into an object file, the C2 ships the object over the wire, and a loader on the target maps it and calls it without …

View comments.

more ...

  • «
  • 1
  • 2
  • 3
  • »

About jm33

Who

  • Resume

Contact

  • Email

  • Mastodon

  • Leave a message

  • Social

    • Twitter
    • GitHub
    • LinkedIn
  • Recent Posts

    • Weaponizing Starlark: Non-Executable Malware and Scriptable C2 Agents
    • Learning AD by Building a C2: Exploiting Constrained Delegation with emp3r0r
    • Learning AD by Building a C2: Exploiting RBCD with emp3r0r
    • Making Linux Malware Suck Less: Stealthy Initial Access with emp3r0r Stager
    • Some Notes on Call Stack Spoofing
  • Tags

    • 404
    • 443
    • active directory
    • ad
    • aes
    • announcement
    • antivirus
    • anyconnect
    • apache
    • arch
    • assembly
    • asu
    • backdoor
    • baidu
    • blackhat
    • bof
    • bridge
    • C#
    • c2
    • censorship
    • cgo
    • cisco
    • cobalt strike
    • code maintainance
    • compton
    • conhost
    • conpty
    • constrained delegation
    • Coursera
    • credential harvesting
    • crypto
    • cryptography
    • CVE
    • CVE-2018-18955
    • CVE-2018-7750
    • dcsync
    • deflate
    • detection
    • Diary
    • DNS污染
    • DPI
    • EDR
    • elf
    • email
    • emp3r0r
    • exploit
    • file transfer
    • gdb
    • gfw
    • ghidra
    • github
    • Glowing Bear
    • golang
    • gpu
    • great wall
    • greatwall
    • hacking
    • hacking tool
    • HiWiFi
    • HTTP2
    • https
    • in-memory
    • injection
    • IRC
    • 极路由
    • KCP
    • kcptun
    • kerberos
    • kernel
    • killer
    • lede
    • libcurl
    • libvirt
    • linux
    • linux-bof
    • linux kernel
    • lkm
    • loader
    • log cleaner
    • LPE
    • macos
    • malware
    • mass exploit
    • mec
    • mentohust
    • Misc
    • mmap
    • mouse
    • multi-threaded crawler
    • namespace
    • natural scroll
    • netcat
    • network
    • nic
    • nim
    • obfs4
    • obfsproxy
    • ocserv
    • openwrt
    • opsec
    • paramiko
    • pentest
    • pep8
    • PGP
    • pi
    • port-forwarding
    • post-exploitation
    • privilege escalation
    • programming
    • project
    • proxy
    • ptrace
    • PTRACE_TRACEME
    • python
    • pythonic
    • qemu
    • QQ
    • rbcd
    • RCE
    • redteam
    • reflective loading
    • reverse shell
    • reversing
    • rootkit
    • s2-045
    • s4u
    • scamware
    • scanner
    • scramblesuit
    • scriptable agent
    • secure boot
    • shadowsocks
    • shadowsocks-plus
    • shell
    • shellcode
    • silentmoonwalk
    • socket
    • srdi
    • SS
    • ssh
    • ssh-harvester
    • sshd
    • SSL
    • stack spoofing
    • stager
    • Stanford
    • starlark
    • sudo
    • switch
    • syscall
    • systemd
    • terminal
    • TMUX
    • tools
    • trasparent proxy
    • vim
    • virtualbox
    • virtualization
    • vpn
    • wayland
    • web
    • weechat
    • windows
    • windows domain
    • windows server
    • x64dbg
    • xfce4
    • xfwm
    • xhost
    • xml
    • zoomeye

© 2026 jm33-ng - About this site

Creative Commons License Content licensed under a Creative Commons Attribution-NonCommercial 4.0 International License, except where indicated otherwise.

Images hosted on this site are either my own or from the Internet