Developer knowledge network · moderated exchange

Супольнасць UnreliableCode

Супольнасць распрацоўшчыкаў даследаванняў, зваротнага праектавання і кадавання

Knowledge indexжыць
4Categories
919Threads
2.8KПаведамленні
Analysis

Stack Frame Unwinding & Return Address Spoofing in x64 Windows

hook_doctor
Hooking Specialist
MEMBER
прадстаўнік: 181
Дата далучэння: Jul 2019
Паведамленні: 21
Дзякуй: 50
3 тыдняў таму · Jul 29, 2026 1:09 PM
#1

How modern anti-cheats detect unauthorized function calls by walking the thread stack:

  1. Anti-cheat hooks internal game functions or analyzes stack frames during exception handlers (RtlCaptureStackBackTrace).
  2. If the return address points to unbacked memory or an unknown non-game module, it flags anomalous call origin.

Return Address Spoofing:
By pushing a legitimate jmp rbx or jmp rax gadget from a signed DLL (e.g. client.dll or ntdll.dll) onto the stack before jumping to the target function, stack walkers see a valid return address pointing inside a signed game module!

x64_assembler
Assembly Guru
MEMBER
прадстаўнік: 99
Дата далучэння: Sep 2022
Паведамленні: 14
Дзякуй: 16
3 тыдняў таму · Jul 29, 2026 3:37 PM
#2

Look for gadget signatures FF 23 (jmp [rbx]) inside legitimate game modules. Clean technique.

kernel_komrade
Driver Dev
MEMBER
прадстаўнік: 145
Дата далучэння: Feb 2019
Паведамленні: 26
Дзякуй: 45
3 тыдняў таму · Jul 30, 2026 5:15 AM
#3

Great overview of call stack spoofing principles.