ELF Symbols and Relocations, a Full `readelf` Session

Toy PIE: readelf -s / -r / -d / -S in one sitting. .dynsym UND vs .symtab, JUMP_SLOT vs RELATIVE, how a stripped copy still names puts. gdb bind check.

September 15, 2026 · 8 min · 1611 words · Jose Adalberto Gutierrez Ochoa

Swift Mangling vs ObjC methname: Recovering Names After Strip

Lab Swift class LabVault: $s… mangled names, xcrun swift demangle, nm before/after strip, the one @objc method that survives in __objc_methname. class-dump, lldb, ASAN. cryptid=1 stops the lab.

March 21, 2025 · 7 min · 1369 words · Jose Adalberto Gutierrez Ochoa

NDK .so Session: readelf, llvm-objdump -d, JNI_OnLoad

One lab APK, one arm64-v8a .so. file/readelf/llvm-objdump through JNI_OnLoad, Java_* exports, GetStringUTFChars, a 32-byte stack copy, tombstone and ASAN. Frida logs length and prefix only.

January 4, 2025 · 7 min · 1414 words · Jose Adalberto Gutierrez Ochoa

AIDL Lab Service: Parcel Layout and Native onTransact

Self-built AIDL service com.lab.binder. dumpsys and logcat Binder, Parcel bytes for writeInterfaceToken + int + string, ARM64 BnEcho::onTransact. No privilege escalation.

February 16, 2024 · 7 min · 1308 words · Jose Adalberto Gutierrez Ochoa

Frida: Java Wrapper vs JNI Interceptor on the Same Call

Lab APK com.lab.jni.trace. Hook NativeBridge.nInit in Java.perform and the Java_* export with Interceptor.attach, then compare argument length and prefix. Console output redacted.

September 4, 2023 · 6 min · 1145 words · Jose Adalberto Gutierrez Ochoa

apktool Smali: if-eqz Chains That Want to Be a switch

Lab APK with packed-looking if-eqz obfuscation around a 5-way dispatch. apktool smali, jadx Java, reconstruct a packed-switch, plus a planted stack copy crash. Not a commercial packer unpack.

November 8, 2022 · 7 min · 1315 words · Jose Adalberto Gutierrez Ochoa

Walking .init_array on a Toy Packed ELF

Lab stub that mprotects RWX, XOR-decodes a 32-byte .text blob, restores r-x, then returns into real code. readelf of .init_array and PT_GNU_STACK, gdb break on mprotect, dump of the r-x region.

July 18, 2022 · 8 min · 1677 words · Jose Adalberto Gutierrez Ochoa

Reversing objc_msgSend on a Self-Signed arm64 Mach-O

otool load commands, class-dump selectors, lldb break on objc_msgSend, recover IMP for -[LabSession startWithToken:], redacted argument log. FairPlay-encrypted App Store bins are out of scope.

October 27, 2021 · 5 min · 958 words · Jose Adalberto Gutierrez Ochoa