u/Pale_Surround_3924

ICMP-Ghost-v3.6.2
▲ 8 r/NetaSec+1 crossposts

ICMP-Ghost-v3.6.2

v3.6.2 update:
Added DNS protocol

Known Issue:

Non-Compliant DNS Tunneling (Wireshark Malformed Packets): Currently, the DNS tunneling module transmits raw Hex/Base32 encoded payloads directly over UDP port 53. Because it lacks strict RFC 1035 headers (e.g., standard Query/Answer structures, QTYPE, QCLASS formatting), packet analyzers like Wireshark and Zeek will flag this traffic as [Malformed Packet].

Workaround/Status: The tunnel is fully operational and reliably transmits data. Full RFC 1035 compliance and fake DNS header wrapping are scheduled for the v4.0 patch to ensure DPI (Deep Packet Inspection) evasion.

github.com
u/Pale_Surround_3924 — 2 days ago

SROP-Assisted Cross-Memory Attach (CMA) Injection via Direct Syscalls.

Hello guys i want to share my last project,

Phantom-Evasion-Loader (x64 Linux):

Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR solutions and Kernel-level monitors like Falco (eBPF). It leverages advanced techniques such as SROP and Zero-Copy Injection to deliver payloads as a ghost in the machine.

github.com
u/Pale_Surround_3924 — 8 days ago