low-level teardowns, reverse engineering, and the occasional bite
A reverse-engineering notebook - driver teardowns, anti-cheat internals, exploitation,
and debugging war stories. Static, no trackers, sources on GitHub. Findings are research
and documentation only.
How AMD’s Anti-Lag+ (Adrenalin 23.10.1) tripped Valve Anti-Cheat in Counter-Strike 2 - a
full static reverse-engineering teardown, from the shipping driver down to the patched bytes
and the one-byte flag that turned it off.
Exploiting a dead phone. Memory-corruption bugs in the decade-old WebKit /
JavaScriptCore that ships on a BlackBerry Bold 9780 (BBOS 6.0.0.294) - reversed to
the addresses and bytes, confirmed on real hardware, and taken as far as an owned
2010 device will safely allow. No ASLR, no NX, no vendor left to report to.
Overwatch 2's 47 MB .text section ships encrypted at entropy 8.000, decrypted lazily one page at a time by Blizzard's Eidolon protector. The pad that decrypts it is 16 KB of plaintext bytes sitting in Overwatch_loader.dll, in the same folder, read circularly across the whole section. 99.84% of the game's code recovered from two files on disk - no key, no memory dump, no running process. Plus the 22 functions Eidolon guts entirely, and an honest account of the four times I fooled myself on the way.