Developer knowledge network · moderated exchange

Супольнасць UnreliableCode

Супольнасць распрацоўшчыкаў даследаванняў, зваротнага праектавання і кадавання

Knowledge indexжыць
4Categories
919Threads
2.8KПаведамленні
Analysis

Stack Frame Unwinding & Return Address Spoofing in x64 Windows Binaries [v2.4 Technical Discussion]

hook_doctor
Hooking Specialist
MEMBER
прадстаўнік: 181
Дата далучэння: Jul 2019
Паведамленні: 21
Дзякуй: 50
2 тыдняў таму · Aug 5, 2026 7:28 PM
#1

How modern anti-cheat modules detect injected DLL function calls:

They walk the call stack (RtlVirtualUnwind) from inside native functions. If the return address points to unbacked / dynamically allocated memory outside valid PE module bounds, the thread is flagged.

Return Address Spoofing Strategy:

  1. Locate a jmp rbx or jmp [rsp] gadget inside a legitimate signed Windows system DLL (kernel32.dll or ntdll.dll).
  2. Overwrite the stack return address with the gadget address.
  3. Restore registers upon function completion.

The unwinder sees the call originating 100% from a signed Microsoft system binary!

stack_smasher
Kernel Explorer
MEMBER
прадстаўнік: 111
Дата далучэння: Feb 2019
Паведамленні: 30
Дзякуй: 18
2 тыдняў таму · Aug 5, 2026 8:40 PM
#2

Return address spoofing is essential when calling internal game engine methods from an injected DLL. Great breakdown of stack unwinding.

vtable_slayer
Senior Reverser
MEMBER
прадстаўнік: 215
Дата далучэння: Mar 2018
Паведамленні: 86
Дзякуй: 61
2 тыдняў таму · Aug 6, 2026 12:30 PM
#3

Masterclass in x64 calling conventions.