+5

Reverse engineer & harness engineer currently at NetEase, previously at Alibaba Cloud, Acxiom, and several startups. Passionate about reverse engineering and vulnerability research, with a primary focus on overseas streaming media and DRM reverse engineering.

Currently diving deep into Widevine L1 Keybox dumping — exploring trusted execution environments, hardware-backed key protection, and the attack surfaces around modern DRM implementations.

Education

  • Beihang University (BUAA)
  • East China University of Science and Technology (ECUST)

Experience

10+ years in the industry as a backend and reverse engineer. Built large-scale systems serving tens of millions of users. Recently focused on reverse engineering & security research: DRM analysis, binary exploitation, TEE attack surfaces, and protocol-level cryptography.

Not a full-stack engineer — more of a full-f*ck engineer. If it breaks, I fix it. If it doesn’t exist, I build it.

Languages & Tools

C/C++, Go, JavaScript, Python, Java

Interests

  • DRM internals & content protection systems
  • Reverse engineering (Android native, TEE, embedded)
  • Vulnerability research & exploit development
  • Cryptography in real-world protocols

Projects

🔬 Reverse Engineering Blog — Writeups, tools, and methodology for binary analysis, DRM research, and protocol reverse engineering.

Contact

📧 overkazaf@gmail.com 💬 WeChat: _0xAF_ (please mention your purpose when adding)

Disclaimer

All research published on this site is strictly for academic and security research purposes. No functional exploit code, working keys, or usable tools are provided. Case studies are presented solely to illustrate reverse engineering methodology and cryptographic analysis techniques.

If any content on this site raises concerns regarding intellectual property or infringes on your rights, please contact me at overkazaf@gmail.com — I will promptly revise or remove the material in question.