56,966 blogs · [ { "id": "01a087ad-caba-72e5-a6e7-00ee09ab404b", "title": "The Trailer Frame Bug Class: RFC 9114 §4.1 as a Universal HTTP/3 State Machine Attack Surface", "url": "https://netacoding.com/posts/h3_trailer_bug_class/", "published_at": "2026-09-04T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0a28c1b3", "title": "WebTransport Zombie Connections: RFC 9114 Trailer Frame Triggers Permanent Stream Leak & OOM in Microsoft Edge and Chromium | Protocol RE", "url": "https://netacoding.com/posts/webtransport-zombie/", "published_at": "2026-09-03T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0a6cdfb7", "title": "ROCm Windows RDNA 4: Fixing hipLaunchKernel 0xC0000005 via Binary Patch", "url": "https://netacoding.com/posts/amdhip64-patch/", "published_at": "2026-08-31T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0b14ec4b", "title": "When Obfuscation Becomes the Signature: Static Analysis of a Go-Based Linux RAT", "url": "https://netacoding.com/posts/warp-rat-elf-static-analysis/", "published_at": "2026-08-18T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0b5e4bb8", "title": "HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE", "url": "https://netacoding.com/posts/blog_post_esf_h3/", "published_at": "2026-08-09T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0c4faf43", "title": "SHA-256 Output Distribution Analysis: Deterministic Cycles, Basin Topology & 42x Rainbow Chain Speedup via CDP", "url": "https://netacoding.com/posts/cdp-sha256-structural-analysis/", "published_at": "2026-07-26T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0cbf3189", "title": "Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE", "url": "https://netacoding.com/posts/windows-icmp-timestamp-bugs/", "published_at": "2026-07-24T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0d75a1df", "title": "ICMP-Ghost: Fileless C2 with ICMP & DNS Tunneling in Pure x64 Assembly | Suricata Bypassed", "url": "https://netacoding.com/posts/icmp-ghost/", "published_at": "2026-07-20T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0e40c15a", "title": "ICMP Timestamp Type 13/14 Linux Kernel Internals: RFC 792 Deviations & ftrace Call Chain Analysis", "url": "https://netacoding.com/posts/icmp-timestamp-internals/", "published_at": "2026-07-07T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0ed45791", "title": "Linux x64 Syscall Table", "url": "https://netacoding.com/tools/syscall-table/", "published_at": "2026-06-30T00:00:00+00:00" }, { "id": "01a087ad-caba-72e5-a6e7-00ee0f7ab4db", "title": "HTTP Request Smuggling: CL.TE, TE.CL & H2 Downgrade | WAF Bypass, Credential Capture & Proxy Chain Exploitation", "url": "https://netacoding.com/posts/http-request-smuggling/", "published_at": "2026-06-21T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5706c70527", "title": "CWE-290 Layer 3: IP Source Spoofing via Missing uRPF | Smurf Amplification, ICMP Leak & Pre-Auth Reflection in ArubaOS", "url": "https://netacoding.com/posts/cwe-290/", "published_at": "2026-06-07T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57077d1de7", "title": "EtherLeak: ICMP Kernel Memory Disclosure via Ethernet Padding | CVE-2003-0001 & CVE-2021-3031", "url": "https://netacoding.com/posts/etherleak-reloaded/", "published_at": "2026-06-05T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57080ac53a", "title": "Smurf Amplification in 2026: Pre-Auth ICMP Reflection via L2 Broadcast | CVE-1999-0513 & Enterprise VLAN", "url": "https://netacoding.com/posts/smurf-amplification/", "published_at": "2026-06-05T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5708e731f6", "title": "ArubaOS 8.13.2.0 Pre-Auth ICMP Buffer Over-read: EtherLeak via TTL=0 + IP Total Length | HPE Bugcrowd", "url": "https://netacoding.com/posts/ghost-leak/", "published_at": "2026-06-01T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570914a386", "title": "ArubaOS 8.13.2.0 Pre-Auth XXE → OOB SSRF & Internal Port Scan on Port 32000 | CWE-611 HPE Bugcrowd", "url": "https://netacoding.com/posts/xxe-ssrf/", "published_at": "2026-06-01T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57099c4be5", "title": "ArubaOS 8.13.2.0 Smurf Amplification & ICMP Reflection: Pre-Auth uRPF Missing + Broadcast Reply | HPE Bugcrowd N/A", "url": "https://netacoding.com/posts/smurf-reflection/", "published_at": "2026-06-01T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570a795cba", "title": "DNS State Exhaustion: Water Torture, NXNS Amplification, TsuNAME & DoT/DoH Socket Starvation", "url": "https://netacoding.com/posts/dns-state-exhaustion/", "published_at": "2026-05-11T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570a8f2149", "title": "TCP State Exhaustion: TIME_WAIT Flood, Sockstress Persist Timer Abuse & Conntrack DoS | Linux Kernel", "url": "https://netacoding.com/posts/tcp-state-exhaustion/", "published_at": "2026-05-11T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570b276414", "title": "BYOVD vs User-Space Injection: EDR Evasion Comparison | SROP + process_vm_writev vs Kernel Driver Exploit", "url": "https://netacoding.com/posts/byovd-vs_userspace_inj/", "published_at": "2026-04-29T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570b5045b1", "title": "FUSE Linux Kernel Integer Overflow: pgoff_t Arithmetic Wrap, Maple Tree OOB Write & VMA Corruption", "url": "https://netacoding.com/posts/fuse-boundary-mathematics-pgoff-overflow/", "published_at": "2026-04-29T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570bc921e4", "title": "FUSE Linux Kernel UAF: drop_caches + SIGKILL Race Condition | DirtyCred Use-After-Free & LPE", "url": "https://netacoding.com/posts/fuse-async-abort-race-double-put/", "published_at": "2026-04-29T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570bf1fd89", "title": "FUSE Trust Boundary Attack: Malicious Daemon i_size Desync → Kernel Heap Overflow via finit_module & kexec", "url": "https://netacoding.com/posts/fuse-trust-boundary-and-size-desync/", "published_at": "2026-04-29T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570c3277ce", "title": "Pure Assembly vs C/Rust Malware Evasion: 0/65 VirusTotal, SROP CFG Bypass & Zero Compiler Artifacts", "url": "https://netacoding.com/posts/language_malware-evasion/", "published_at": "2026-04-25T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570c78bca4", "title": "LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs", "url": "https://netacoding.com/posts/lockbit5-analysis/", "published_at": "2026-04-23T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570ce1f0ce", "title": "AI Agent Security: Why Container Isolation & Linux RBAC Beat AI Firewalls | Kernel-Level Access Control", "url": "https://netacoding.com/posts/ai-universal-rule/", "published_at": "2026-04-21T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570d142fcd", "title": "LCG Jitter x64 Assembly: Randomized nanosleep for C2 Beaconing Evasion & SOC Behavioral Detection Bypass", "url": "https://netacoding.com/posts/lcg-jitter/", "published_at": "2026-04-20T07:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570df57da7", "title": "CFG Flattening with CMOV: Antivirus & EDR Evasion via Control Flow Obfuscation in x64 Assembly", "url": "https://netacoding.com/posts/polymorphic/", "published_at": "2026-04-15T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570eaa8024", "title": "Phantom Evasion Loader: SROP + process_vm_writev Direct Cross-Memory Shellcode Injection | EDR & Falco Bypass in x64 Assembly", "url": "https://netacoding.com/posts/phantom-evasion-loader-blog/", "published_at": "2026-04-13T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570efc45f7", "title": "VESQER: DPCM+RLE Hybrid Shellcode Compression in x64 Assembly | C2 Payload Size Reduction & OPSEC", "url": "https://netacoding.com/posts/compressdpcm-rle/", "published_at": "2026-04-11T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d570f7b168c", "title": "Position Independent Code (PIC) in x64 Assembly: Stack Anchor Technique, Sectionless Shellcode & ASLR-Safe Payloads", "url": "https://netacoding.com/posts/pic-entry/", "published_at": "2026-04-03T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57105e95ac", "title": "TCP Reverse Shell in Pure x64 Assembly: PIC Shellcode, Syscall Chain & dup2 FD Redirection | No libc", "url": "https://netacoding.com/posts/reverse_shell-assembly/", "published_at": "2026-04-03T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57111101b0", "title": "Bare-Metal HTTP Server in x86_64 Assembly: sys_sendfile Zero-Copy, Raw Sockets & Path Traversal Prevention | No libc", "url": "https://netacoding.com/posts/assembly-httpserver/", "published_at": "2026-03-29T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57112843cf", "title": "About Me", "url": "https://netacoding.com/about/", "published_at": "2026-03-27T10:50:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57117c0d52", "title": "Contact", "url": "https://netacoding.com/contact/", "published_at": "2026-03-27T10:45:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d571276dd0b", "title": "RDTSC Network Timing & Jitter Analysis in x64 Assembly: Nanosecond Packet Measurement & SOC Detection Evasion", "url": "https://netacoding.com/posts/statistical-jitter/", "published_at": "2026-03-27T08:31:43+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5712d93f3e", "title": "memfd_create Linux: Fileless In-Memory Execution & Anti-Forensics via Syscall 319 in x64 Assembly", "url": "https://netacoding.com/posts/volatile-storage/", "published_at": "2026-03-27T08:30:25+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57134a4660", "title": "Linux x64 Assembly Syscall ABI: Registers, File Descriptors & .bss Segment | open, read, write, exit", "url": "https://netacoding.com/posts/syscall-bss/", "published_at": "2026-03-27T08:27:01+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5713bbbb12", "title": "CVE-2025-6019: udisks2 TOCTOU Race Condition → Local Privilege Escalation | Polkit Bypass & SUID Exploit", "url": "https://netacoding.com/posts/udisks2-cve_lpe/", "published_at": "2026-03-27T08:20:47+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57144250a4", "title": "eBPF Linux: XDP Packet Filtering, Kprobes Runtime Tracing & Kernel-Level Malware Detection", "url": "https://netacoding.com/posts/ebpf/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5714bd64db", "title": "ICMP C2 Evasion: IDS/IPS Bypass via Traffic Mimicry, RDTSC Timestamping & Stateless Port Knocking | Suricata", "url": "https://netacoding.com/posts/advanced-evasion-techniques/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5715b326a8", "title": "ICMP OS Fingerprinting & NIDS Evasion: Traffic Mimicry via Linux/Windows Payload Signatures in x64 Assembly", "url": "https://netacoding.com/posts/network-fingerprinting/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d571614934b", "title": "ICMP Packet Sniffer in x64 Assembly: Raw Socket Capture, Header Stripping & Binary-to-ASCII IP | No libc", "url": "https://netacoding.com/posts/icmp_sniffer/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5716a6d995", "title": "ICMP Type 3 Protocol Encapsulation: Nested ICMP Firewall Bypass & DPI Evasion via 0xFFFF Boundary Flaw", "url": "https://netacoding.com/posts/icmp_encapsulation/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d57174f56fe", "title": "IP Endianness in x64 Assembly: Big-Endian Network Byte Order to ASCII | Single-Pass div Algorithm Without inet_ntoa", "url": "https://netacoding.com/posts/algorithmforprinting-ip_addresses/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5717f0771e", "title": "Linux Anti-Debugging & Memory Dump Prevention: ptrace + prctl in x64 Assembly | EDR Evasion", "url": "https://netacoding.com/posts/anti-analysis/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5718b33d38", "title": "RFC 1071 One's Complement Checksum in x64 Assembly: ICMP Carry Folding, Odd-Byte Handling & Packet Verification", "url": "https://netacoding.com/posts/rfc-1071/", "published_at": "2026-03-27T00:00:00+00:00" }, { "id": "01a087ad-cabb-7266-ac74-6d5719a357df", "title": "Encoders & Decoders", "url": "https://netacoding.com/tools/encoders/", "published_at": null }, { "id": "01a087ad-cabb-7266-ac74-6d5719b42852", "title": "Hash Generator", "url": "https://netacoding.com/tools/hash-generator/", "published_at": null }, { "id": "01a087ad-cabb-7266-ac74-6d5719f48565", "title": "IP Subnet & CIDR Calculator", "url": "https://netacoding.com/tools/ip-calc/", "published_at": null }, { "id": "01a087ad-cabb-7266-ac74-6d571a41c4bb", "title": "MAC Address Tools", "url": "https://netacoding.com/tools/mac-tools/", "published_at": null }, { "id": "01a087ad-cabb-7266-ac74-6d571adbfdf5", "title": "Secure Password Generator", "url": "https://netacoding.com/tools/password-gen/", "published_at": null }, { "id": "01a087ad-cabb-7266-ac74-6d571afd9087", "title": "SysAdmin & Forensics", "url": "https://netacoding.com/tools/sysadmin-tools/", "published_at": null } ] posts Claim your blog
Back to netacoding.com
Blog · corpus.blog/blogs/netacoding.com/posts

netacoding.com

netacoding.com

2026

Undated