Netacoding 🛡️

Dedicated to Low-Level Research and Cybersecurity Tools. Analyze internet protocols, master Assembly language, and use our professional-grade security toolkit for daily operations.
42 posts · ... stars · JM00NJ

ROCm Windows RDNA 4: Fixing hipLaunchKernel 0xC0000005 via Binary Patch

On Windows ROCm 7.14 + RX 9070 XT (gfx1201/RDNA 4), any HIP kernel dispatch crashes with STATUS_ACCESS_VIOLATION. WinDbg live debugging reveals a garbage pointer in the ROCprofiler callback linked list inside hipProfilerRegisterChunkCallbackExt. A first patch targeting hipLaunchKernel+0x85 stopped the crash but silenced all GPU compute — tensors returned zero. The correct fix patches hipProfilerRegisterChunkCallbackExt itself to immediately return 0, leaving kernel dispatch intact.

August 31, 2026 · 8 min · JM00NJ
ROCm Windows RDNA 4: Fixing hipLaunchKernel 0xC0000005 via Binary Patch

When Obfuscation Becomes the Signature: Static Analysis of a Go-Based Linux RAT

Static analysis of a Go-based Linux RAT (Warp/Wraith family, SHA256: 3bfc4394…) that manipulates its ELF structure to evade analysis tools. Three structural anomalies — section header table past EOF, oversized PT_LOAD segment, and dynamic linking on a Go binary — produce an immediate malicious verdict before any disassembly runs. String analysis identifies SSH/SFTP credential harvesting, /bin/systemd-worker process masquerading, and a related 736KB variant (e097c852…) with embedded coinminer payload. Detected via static ELF header inspection alone, no sandbox required.

August 18, 2026 · 6 min · JM00NJ
When Obfuscation Becomes the Signature: Static Analysis of a Go-Based Linux RAT

HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE

A second HEADERS frame (RFC 9114 §4.1 trailer) on a YouTube ESF request stream causes a ~60-second server-side hang followed by QUIC INTERNAL_ERROR 0x0001, indicating an unhandled exception in ESF’s HTTP/3 state machine. The crash bypasses HTTP-layer rate limiting and WAF controls architecturally — the connection terminates at the transport layer before any HTTP request object is created. Confirmed deterministically across 3/3 runs. Google VRP declined to track as a security issue. Full PoC and cross-vendor evidence included.

August 9, 2026 · 6 min · JM00NJ
HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE

SHA-256 Output Distribution Analysis: Deterministic Cycles, Basin Topology & 42x Rainbow Chain Speedup via CDP

SHA-256 output distribution is not featureless. CDP projects each 64-hex-digit output to a scalar weight W ∈ [434,555] across 961 classes, revealing a Cycle-1 (476↔438 fixed point), an 8-node Cycle-2, and strongly asymmetric basin topology. The 38.6x scalar pre-filter achieves zero false negatives. Compound triple constraint delivers 42.55x rainbow chain speedup — 16.6x beyond the published literature best of 2.56x. OpenCL implementation included.

July 26, 2026 · 10 min · JM00NJ
SHA-256 Output Distribution Analysis: Deterministic Cycles, Basin Topology & 42x Rainbow Chain Speedup via CDP

Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE

The Windows registry key EnableICMPTimestampRep=0 is silently ignored by tcpip.sys — Ipv4pHandleTimestampRequest generates ICMP Type 14 replies unconditionally regardless of the registry value. Ghidra static analysis of tcpip.sys 10.0.26100.8457 reveals a second RFC 792 violation: Receive and Transmit timestamps are written in little-endian byte order while the adjacent IP Timestamp Option handler correctly calls htonl() on the same value. Confirmed via pcap, netstat ICMP counters, and WinDbg kernel breakpoints. CVE-1999-0524 scope analysis and WFP mitigation rule included.

July 24, 2026 · 11 min · JM00NJ
Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE
DigitalOcean Referral Badge