pwn.dog

pwn.dog

low-level teardowns, reverse engineering, and the occasional bite

A reverse-engineering notebook - driver teardowns, anti-cheat internals, exploitation, and debugging war stories. Static, no trackers, sources on GitHub. Findings are research and documentation only.

How AMD’s Anti-Lag+ (Adrenalin 23.10.1) tripped Valve Anti-Cheat in Counter-Strike 2 - a full static reverse-engineering teardown, from the shipping driver down to the patched bytes and the one-byte flag that turned it off.

  1. Detouring Yourself Into a Ban: Reverse-Engineering AMD Anti-Lag+
  2. The Engine Room: AMD's Detours-Based Hook Library (amdihk64)
  3. The Control Plane: How One Byte in a Profile Blob Disabled Anti-Lag+
  4. Indistinguishable: What VAC Checks For, and Why Anti-Lag+ Never Stood a Chance

16 Kilobytes in the Clear: Decrypting Overwatch 2 Without Running It

Overwatch 2's 47 MB .text section ships encrypted at entropy 8.000, decrypted lazily one page at a time by Blizzard's Eidolon protector. The pad that decrypts it is 16 KB of plaintext bytes sitting in Overwatch_loader.dll, in the same folder, read circularly across the whole section. 99.84% of the game's code recovered from two files on disk - no key, no memory dump, no running process. Plus the 22 functions Eidolon guts entirely, and an honest account of the four times I fooled myself on the way.