jm33_ng
  • Malware
  • Misc
  • Programming
  • R&d
  • Tools
  • Vulnerabilities
  • RSS

jm33_ng


cyber security / noob developer / poor English

Some Notes on Call Stack Spoofing

Date Fri 21 August 2026 Tags windows / malware / stack spoofing / silentmoonwalk / emp3r0r / c2 / EDR

spoofed call stack

The Basics

Forgive me if this post sounds too basic or detailed. My tutor job gave me this style. Hopefully it helps beginners.

The screenshots are taken from different runs as I didn't have the time to finish writing in one go. If you see different addresses, that's why.

What …

View comments.

more ...

About jm33

Who

  • Resume

Contact

  • Email

  • Mastodon

  • Leave a message

  • Social

    • Twitter
    • GitHub
    • LinkedIn
  • Recent Posts

    • Some Notes on Call Stack Spoofing
  • Tags

    • 404
    • 443
    • active directory
    • ad
    • aes
    • announcement
    • antivirus
    • anyconnect
    • apache
    • arch
    • assembly
    • asu
    • backdoor
    • baidu
    • blackhat
    • bof
    • bridge
    • C#
    • c2
    • censorship
    • cgo
    • cisco
    • cobalt strike
    • code maintainance
    • compton
    • conhost
    • conpty
    • Coursera
    • credential harvesting
    • crypto
    • cryptography
    • CVE
    • CVE-2018-18955
    • CVE-2018-7750
    • deflate
    • Diary
    • DNS污染
    • DPI
    • EDR
    • elf
    • email
    • emp3r0r
    • exploit
    • file transfer
    • gdb
    • gfw
    • ghidra
    • github
    • Glowing Bear
    • golang
    • gpu
    • great wall
    • greatwall
    • hacking
    • hacking tool
    • HiWiFi
    • HTTP2
    • https
    • in-memory
    • injection
    • IRC
    • 极路由
    • KCP
    • kcptun
    • kernel
    • killer
    • lede
    • libcurl
    • libvirt
    • linux
    • linux-bof
    • linux kernel
    • lkm
    • loader
    • log cleaner
    • LPE
    • macos
    • malware
    • mass exploit
    • mec
    • mentohust
    • Misc
    • mmap
    • mouse
    • multi-threaded crawler
    • namespace
    • natural scroll
    • netcat
    • network
    • nic
    • nim
    • obfs4
    • obfsproxy
    • ocserv
    • openwrt
    • paramiko
    • pentest
    • pep8
    • PGP
    • pi
    • port-forwarding
    • post-exploitation
    • privilege escalation
    • programming
    • project
    • proxy
    • ptrace
    • PTRACE_TRACEME
    • python
    • pythonic
    • qemu
    • QQ
    • RCE
    • redteam
    • reflective loading
    • reverse shell
    • reversing
    • rootkit
    • s2-045
    • scamware
    • scanner
    • scramblesuit
    • secure boot
    • shadowsocks
    • shadowsocks-plus
    • shell
    • shellcode
    • silentmoonwalk
    • socket
    • srdi
    • SS
    • ssh
    • ssh-harvester
    • sshd
    • SSL
    • stack spoofing
    • Stanford
    • sudo
    • switch
    • syscall
    • systemd
    • terminal
    • TMUX
    • tools
    • trasparent proxy
    • vim
    • virtualbox
    • virtualization
    • vpn
    • wayland
    • web
    • weechat
    • windows
    • windows domain
    • windows server
    • x64dbg
    • xfce4
    • xfwm
    • xhost
    • xml
    • zoomeye

© 2026 jm33-ng - About this site

Creative Commons License Content licensed under a Creative Commons Attribution-NonCommercial 4.0 International License, except where indicated otherwise.

Images hosted on this site are either my own or from the Internet