<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Reverse engineering · Patrik Grobshäuser</title>
    <link>https://patrik.re/topics/reverse-engineering/</link>
    <description>Firmware, debuggers, and understanding what software does underneath.</description>
    <language>en-GB</language>
    <atom:link href="https://patrik.re/topics/reverse-engineering/index.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Wed, 18 Mar 2026 00:00:00 &#43;0000</lastBuildDate>
    <item>
      <title>Hyoketsu — Solving the Vendor Dependency Problem in RE</title>
      <link>https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re/</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>Tooling for reverse engineering without waiting on vendor firmware.</description>
      <category>Searchlight Cyber</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Android certificate pinning bypass with Frida</title>
      <link>https://patrik.re/the-stony-path-of-android--f0-9f-a4-96-bug-bounty-bypassing-certificate-pinning/</link>
      <guid isPermaLink="true">https://patrik.re/the-stony-path-of-android--f0-9f-a4-96-bug-bounty-bypassing-certificate-pinning/</guid>
      <pubDate>Sat, 21 Oct 2017 00:00:00 &#43;0000</pubDate>
      <description>A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.</description>
      <category>patrik.re</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Shopify POS firmware: extracting a root hash</title>
      <link>https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</link>
      <guid isPermaLink="true">https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</guid>
      <pubDate>Fri, 09 Oct 2015 00:00:00 &#43;0000</pubDate>
      <description>An in-scope Shopify POS endpoint exposed the card reader&#39;s firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Stop OS X Spotlight Leaking Your Location</title>
      <link>https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</link>
      <guid isPermaLink="true">https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</guid>
      <pubDate>Mon, 15 Jun 2015 00:00:00 &#43;0000</pubDate>
      <description>Proxying OS X Spotlight through Burp showed it shipping the user&#39;s latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>iTunes anti-debugging bypass with GDB and LLDB</title>
      <link>https://patrik.re/itunes-exploit-development/</link>
      <guid isPermaLink="true">https://patrik.re/itunes-exploit-development/</guid>
      <pubDate>Sun, 10 Mar 2013 00:00:00 &#43;0000</pubDate>
      <description>Defeating iTunes&#39; ptrace-based anti-debugging on OS X by breaking on ptrace and rewriting the rdi register, and porting the bypass from Apple&#39;s GDB to LLDB to get a Python-capable debugger.</description>
      <category>patrik.re</category><category>reverse-engineering</category>
    </item>
  </channel>
</rss>
