jm33_ng
  • Malware
  • Misc
  • Programming
  • R&d
  • Tools
  • Vulnerabilities
  • RSS

jm33_ng


cyber security / noob developer / poor English

Some Notes on Call Stack Spoofing

Date Fri 21 August 2026 Tags windows / malware / stack spoofing / silentmoonwalk / emp3r0r / c2 / EDR

spoofed call stack

The Basics

Forgive me if this post sounds too basic or detailed. My tutor job gave me this style. Hopefully it helps beginners.

The screenshots are taken from different runs as I didn't have the time to finish writing in one go. If you see different addresses, that's why.

What …

View comments.

more ...

Writing a Linux BOF Loader from Scratch

Date Sat 17 January 2026 Tags linux-bof / linux / elf / in-memory / emp3r0r / mmap / bof / cobalt strike / c2

banner

Introduction

Beacon Object Files (BOFs) have revolutionized the way we execute code in memory on Windows systems, particularly within the Cobalt Strike framework. As you may know, I have been working on my own C2 framework, emp3r0r, which aims to bring similar capabilities to Linux environments. In this post, I …

View comments.

more ...

  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • »

About jm33

Who

  • Resume

Contact

  • Email

  • Mastodon

  • Leave a message

  • Social

    • Twitter
    • GitHub
    • LinkedIn
  • Recent Posts

    • Some Notes on Call Stack Spoofing
    • Writing a Linux BOF Loader from Scratch
    • sRDI for Linux: Stealthy In-Memory ELF Loading
    • OpenSSH Server 密码收割机
    • Fully Interactive Remote Shell for Windows
  • Tags

    • 404
    • 443
    • active directory
    • ad
    • aes
    • announcement
    • antivirus
    • anyconnect
    • apache
    • arch
    • assembly
    • asu
    • backdoor
    • baidu
    • blackhat
    • bof
    • bridge
    • C#
    • c2
    • censorship
    • cgo
    • cisco
    • cobalt strike
    • code maintainance
    • compton
    • conhost
    • conpty
    • Coursera
    • credential harvesting
    • crypto
    • cryptography
    • CVE
    • CVE-2018-18955
    • CVE-2018-7750
    • deflate
    • Diary
    • DNS污染
    • DPI
    • EDR
    • elf
    • email
    • emp3r0r
    • exploit
    • file transfer
    • gdb
    • gfw
    • ghidra
    • github
    • Glowing Bear
    • golang
    • gpu
    • great wall
    • greatwall
    • hacking
    • hacking tool
    • HiWiFi
    • HTTP2
    • https
    • in-memory
    • injection
    • IRC
    • 极路由
    • KCP
    • kcptun
    • kernel
    • killer
    • lede
    • libcurl
    • libvirt
    • linux
    • linux-bof
    • linux kernel
    • lkm
    • loader
    • log cleaner
    • LPE
    • macos
    • malware
    • mass exploit
    • mec
    • mentohust
    • Misc
    • mmap
    • mouse
    • multi-threaded crawler
    • namespace
    • natural scroll
    • netcat
    • network
    • nic
    • nim
    • obfs4
    • obfsproxy
    • ocserv
    • openwrt
    • paramiko
    • pentest
    • pep8
    • PGP
    • pi
    • port-forwarding
    • post-exploitation
    • privilege escalation
    • programming
    • project
    • proxy
    • ptrace
    • PTRACE_TRACEME
    • python
    • pythonic
    • qemu
    • QQ
    • RCE
    • redteam
    • reflective loading
    • reverse shell
    • reversing
    • rootkit
    • s2-045
    • scamware
    • scanner
    • scramblesuit
    • secure boot
    • shadowsocks
    • shadowsocks-plus
    • shell
    • shellcode
    • silentmoonwalk
    • socket
    • srdi
    • SS
    • ssh
    • ssh-harvester
    • sshd
    • SSL
    • stack spoofing
    • Stanford
    • sudo
    • switch
    • syscall
    • systemd
    • terminal
    • TMUX
    • tools
    • trasparent proxy
    • vim
    • virtualbox
    • virtualization
    • vpn
    • wayland
    • web
    • weechat
    • windows
    • windows domain
    • windows server
    • x64dbg
    • xfce4
    • xfwm
    • xhost
    • xml
    • zoomeye

© 2026 jm33-ng - About this site

Creative Commons License Content licensed under a Creative Commons Attribution-NonCommercial 4.0 International License, except where indicated otherwise.

Images hosted on this site are either my own or from the Internet