↓ Skip to main content

Reverse engineering

Firmware, debuggers, and understanding what software does underneath.

2026

2017

patrik.re Archive

Android certificate pinning bypass with Frida

A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.

2015

patrik.re

Shopify POS firmware: extracting a root hash

An in-scope Shopify POS endpoint exposed the card reader's firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.

patrik.re Archive

Stop OS X Spotlight Leaking Your Location

Proxying OS X Spotlight through Burp showed it shipping the user's latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.

2013

patrik.re

iTunes anti-debugging bypass with GDB and LLDB

Defeating iTunes' ptrace-based anti-debugging on OS X by breaking on ptrace and rewriting the rdi register, and porting the bypass from Apple's GDB to LLDB to get a Python-capable debugger.