Hyoketsu — Solving the Vendor Dependency Problem in RE ↗
Tooling for reverse engineering without waiting on vendor firmware.
Firmware, debuggers, and understanding what software does underneath.
Tooling for reverse engineering without waiting on vendor firmware.
A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.
An in-scope Shopify POS endpoint exposed the card reader's firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.
Proxying OS X Spotlight through Burp showed it shipping the user's latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.
Defeating iTunes' ptrace-based anti-debugging on OS X by breaking on ptrace and rewriting the rdi register, and porting the bypass from Apple's GDB to LLDB to get a Python-capable debugger.