Swift Mangling vs ObjC methname: Recovering Names After Strip

Lab Swift class LabVault: $s… mangled names, xcrun swift demangle, nm before/after strip, the one @objc method that survives in __objc_methname. class-dump, lldb, ASAN. cryptid=1 stops the lab.

March 21, 2025 · 7 min · 1369 words · Jose Adalberto Gutierrez Ochoa

NDK .so Session: readelf, llvm-objdump -d, JNI_OnLoad

One lab APK, one arm64-v8a .so. file/readelf/llvm-objdump through JNI_OnLoad, Java_* exports, GetStringUTFChars, a 32-byte stack copy, tombstone and ASAN. Frida logs length and prefix only.

January 4, 2025 · 7 min · 1414 words · Jose Adalberto Gutierrez Ochoa

Symbolicating a Lab Crash When UIKit Lives in the dyld Shared Cache

Lab crash on a self-signed LabSession: dwarfdump -u, atos against the dSYM, why UIKit frames are not in nm of the app, crash report with [REDACTED] paths. No DSC extraction. cryptid=1 stops the lab.

August 19, 2024 · 6 min · 1184 words · Jose Adalberto Gutierrez Ochoa

AIDL Lab Service: Parcel Layout and Native onTransact

Self-built AIDL service com.lab.binder. dumpsys and logcat Binder, Parcel bytes for writeInterfaceToken + int + string, ARM64 BnEcho::onTransact. No privilege escalation.

February 16, 2024 · 7 min · 1308 words · Jose Adalberto Gutierrez Ochoa

Frida: Java Wrapper vs JNI Interceptor on the Same Call

Lab APK com.lab.jni.trace. Hook NativeBridge.nInit in Java.perform and the Java_* export with Interceptor.attach, then compare argument length and prefix. Console output redacted.

September 4, 2023 · 6 min · 1145 words · Jose Adalberto Gutierrez Ochoa

Reversing objc_msgSend on a Self-Signed arm64 Mach-O

otool load commands, class-dump selectors, lldb break on objc_msgSend, recover IMP for -[LabSession startWithToken:], redacted argument log. FairPlay-encrypted App Store bins are out of scope.

October 27, 2021 · 5 min · 958 words · Jose Adalberto Gutierrez Ochoa

Finding Hidden JNI Methods: RegisterNatives in a Lab APK

APK where nm -D shows no Java_* exports. Walk JNI_OnLoad, recover the JNINativeMethod table, map Java names to ARM64 IMPs, Frida-trace the native with arguments redacted.

June 9, 2021 · 5 min · 950 words · Jose Adalberto Gutierrez Ochoa

Recovering a C++ Vtable From ARM64/x64 Disassembly

Two-class toy hierarchy, virtual dtor plus two methods. objdump/readelf of the compiler vtable, ctor writing the vptr, virtual call through [x0,#16], gdb print of the slot.

March 11, 2021 · 9 min · 1866 words · Jose Adalberto Gutierrez Ochoa