Art of Shellcoding

Background
share close

ART OF SHELLCODING

From Linux system calls to compact, encoded and polymorphic payloads.

This restored nine-part research archive preserves Nipun Jaswal’s Linux x86 shellcode-engineering series originally published in 2018. The articles document payload construction, byte-level optimisation, reverse engineering, egghunting, encoding, polymorphism and runtime decryption.

The original publication dates, SLAE-1080 attribution, screenshots and public source-code references have been retained, with modern archival context and responsible-use notices added to every article.

Start with Part 1
View Exploit-DB Profile
Background
Research Context

A PRACTICAL ASSEMBLY-LEVEL LEARNING JOURNEY

Created through the SecurityTube Linux Assembly Expert programme under student ID SLAE-1080 and preserved as part of the public research record.


Construct

Build bind and reverse TCP shellcode from Linux system-call behaviour rather than treating payload bytes as an opaque sequence.

Optimise

Reduce size, avoid selected bad characters, reuse registers and understand the byte-level cost of individual instructions.

Analyse and transform

Study egghunting, disassembly, custom encoding, polymorphism and encryption through debugger-led validation.

The Complete Series

NINE PARTS OF SHELLCODE ENGINEERING

Read the archive in its original sequence. Each article includes previous, next and series-hub navigation.


01 — The Saga of Bind TCP Shell

2 January 2018

Metasploit payload analysis, custom Linux x86 construction, null-byte removal, dynamic port generation and reduction from 108 to 80 bytes.

Read Part 1 →

02 — Tale of the Smallest Reverse TCP Shellcode

5 January 2018

A compact null-free reverse TCP payload with an IP-and-port wrapper, accepted by Exploit-DB as EDB-ID 43433.

Read Part 2 →

03 — Cracking Eggs with EggHunters

16 January 2018

A compact memory-scanning stage designed to locate and transfer execution to a larger payload when available exploit space is constrained.

Read Part 3 →


04 — The MultiEncoder Shellcode (RNX2)

6 February 2018

A custom XOR, XOR, NOT and offset encoding chain with an assembly decoder and byte-by-byte debugger validation.

Read Part 4 →

05 — Metasploit Add User Payload Analysis

10 February 2018

Disassembly of the Linux x86 add-user payload and its setreuid, open, write and exit system-call sequence.

Read Part 5 →

06 — IPv6 Reverse TCP Shellcode Analysis

23 February 2018

A libemu- and strace-assisted examination of Metasploit’s IPv6 reverse TCP payload and its differences from IPv4.

Read Part 6 →


07 — Metasploit Read File Payload Analysis

24 February 2018

GDB-PEDA analysis of the open, read, write and exit flow used by the Linux x86 read-file payload.

Read Part 7 →

08 — Polymorphic Shellcodes

28 February 2018

Three payload transformations demonstrating equivalent behaviour through alternative instruction sequences and their size trade-offs.

Read Part 8 →

09 — Basic AES Shellcode Crypter

28 February 2018

A C-based Rijndael-128 proof of concept demonstrating encryption, runtime decryption and controlled execution in a lab environment.

Read Part 9 →

Preservation Standard

ORIGINAL RECORD, RECOVERED EVIDENCE AND MODERN CONTEXT


Original record

Original publication date, research objective, SLAE attribution and public source-code references are preserved throughout the series.

Recovered evidence

Screenshots, debugger output, code references and supporting repository links were restored from the Blogger export and public archives.

2026 context

Every article identifies the historical 32-bit Linux context and explains that modern protections may alter compilation and execution behaviour.


Responsible-use notice: This archive is retained for authorised laboratories, defensive understanding, education and historical research. Test only on systems you own or are explicitly authorised to assess.

Public Research Record

SOURCE CODE, EXPLOIT-DB AND THE ORIGINAL ARCHIVE

Explore the supporting repositories and the wider vulnerability-research record.


View SLAE Source Repository


View Exploit-DB Profile


Explore Vulnerability Research