Binary Auditing Checklist, Filled on a Toy ELF

First-pass checklist actually filled: checksec + readelf + objdump on a 60-line toy with gets/sprintf/printf(user). One-pager of mitigations, sinks, and the ASan crash.

August 21, 2021 · 8 min · 1620 words · Jose Adalberto Gutierrez Ochoa

Finding Hidden JNI Methods: RegisterNatives in a Lab APK

APK where nm -D shows no Java_* exports. Walk JNI_OnLoad, recover the JNINativeMethod table, map Java names to ARM64 IMPs, Frida-trace the native with arguments redacted.

June 9, 2021 · 5 min · 950 words · Jose Adalberto Gutierrez Ochoa

Recovering a C++ Vtable From ARM64/x64 Disassembly

Two-class toy hierarchy, virtual dtor plus two methods. objdump/readelf of the compiler vtable, ctor writing the vptr, virtual call through [x0,#16], gdb print of the slot.

March 11, 2021 · 9 min · 1866 words · Jose Adalberto Gutierrez Ochoa

ROP vs ret2libc: Classifying `ret` Sites on a Toy Binary

Mental model plus objdump of a toy: ret2libc is whole-function reuse, ROP is fragment reuse. Classify epilogue rets vs pop;ret vs leave;ret. Overflow crash with RIP=0x4141… — no system("/bin/sh") chain.

February 9, 2021 · 8 min · 1695 words · Jose Adalberto Gutierrez Ochoa

AArch64 Calling Convention, as Read in IDA

AAPCS64 as it shows up in IDA: x0–x7, x29/x30, 16-byte SP, PACIBSP. Toy function with nine integer args so the ninth is on the stack. objdump of prologue and epilogue.

August 3, 2020 · 9 min · 1822 words · Jose Adalberto Gutierrez Ochoa

Reading RELRO, GOT, and PLT on a PIE Lab Binary

Partial vs Full RELRO measured on one toy: readelf FLAGS/GNU_RELRO, objdump of puts@plt, gdb GOT slot before and after bind, /proc maps of .got.plt. Companion to the lazy-binding lab.

June 15, 2020 · 8 min · 1598 words · Jose Adalberto Gutierrez Ochoa

ELF GOT/PLT Lazy Binding, Read From a PIE Lab Binary

Lab walkthrough of lazy PLT binding on a PIE: readelf, objdump, GOT slot before/after the first call, Partial vs Full RELRO.

April 22, 2020 · 4 min · 833 words · Jose Adalberto Gutierrez Ochoa

Walking Mach-O Load Commands on a Self-Signed arm64 Lab Binary

Full otool -l walk of a self-signed LabSession: mach_header_64, LC_SEGMENT_64 __TEXT/__DATA, LC_LOAD_DYLIB, LC_CODE_SIGNATURE, LC_ENCRYPTION_INFO_64 cryptid=0. size -x, nm, class-dump, lldb. cryptid=1 stops the lab.

January 16, 2020 · 7 min · 1387 words · Jose Adalberto Gutierrez Ochoa