<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Reverse-Engineering on +5 Security Research</title><link>https://overkazaf.github.io/blogs/tags/reverse-engineering/</link><description>Recent content in Reverse-Engineering on +5 Security Research</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://overkazaf.github.io/blogs/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>3.4 秒：一条 TCP 选项改变的 57 倍 - FairPlay DRM 解密管线优化实录</title><link>https://overkazaf.github.io/blogs/posts/fairplay-drm-decrypt-pipeline-optimization/</link><pubDate>Wed, 13 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/fairplay-drm-decrypt-pipeline-optimization/</guid><description>基于 Apple Music FairPlay DRM 解密管线的完整优化记录：从 Nagle 算法导致的 193 秒逐样本同步降至 TCP 管线化的 3.4 秒（57x 提升），再到流式 ISO BMFF 解析器将内存从 181MB 压缩到 11MB（94% 下降），最后用 DFA/DCA 验证了 libCoreFP.so 的第三代白盒 AES 不可攻破</description></item><item><title>五个函数，一条链 - Apple FairPlay DRM 的 Frida 逆向全记录</title><link>https://overkazaf.github.io/blogs/posts/fairplay-drm-frida-reversing/</link><pubDate>Sun, 10 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/fairplay-drm-frida-reversing/</guid><description>通过 Frida 动态插桩 + IDA Pro 静态分析，逐步还原 Apple Music for Android 的 FairPlay DRM 解密调用链：从 Java 层 FootHillDecryptionKey 到 Native 层 SVFootHillSessionCtrl 的 5 个关键函数，最终定位白盒 AES 解密入口 NfcRKVnxuKZy04KWbdFu*** 并实现加密 ALAC 样本的流式 dump</description></item><item><title>四层特权，四条链，一个目标 - ARM TrustZone EL0→EL3 攻击实录</title><link>https://overkazaf.github.io/blogs/posts/arm-trustzone-el0-to-el3-attack-chain-anatomy/</link><pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/arm-trustzone-el0-to-el3-attack-chain-anatomy/</guid><description>以 Quarkslab/Project Zero/360 Alpha Lab 的四条真实攻击链为案例，从 ARM 异常等级架构出发，逐层解剖 EL0→S-EL0→S-EL1→EL3 的提权技术：共享内存机制、SMC 调用约定、Trustlet 漏洞模式、TEE 内核提权、Secure Monitor 劫持，以及 Boot Chain 替代路径</description></item><item><title>谁在铸造破解白盒的武器？ - Quarkslab 十年开源攻防全纪实</title><link>https://overkazaf.github.io/blogs/posts/quarkslab-drm-whitebox-cryptanalysis-arsenal/</link><pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/quarkslab-drm-whitebox-cryptanalysis-arsenal/</guid><description>系统梳理法国安全团队 Quarkslab 在白盒密码破译与 DRM 安全研究领域的十年技术演进：从 CHES 2016 最佳论文到 SideChannelMarvels 开源武器库，从 Samsung TrustZone EL3 代码执行到 DarkPhoenix/BlueGalaxyEnergy 新一代工具链</description></item><item><title>13 种攻击全部失败之后 - Chrome Widevine CDM 白盒 AES 的工程突围</title><link>https://overkazaf.github.io/blogs/posts/chrome-cdm-stream-dump-widevine-vtable-hook/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/chrome-cdm-stream-dump-widevine-vtable-hook/</guid><description>在 Chrome Linux Widevine CDM 4.10.2934 上尝试 13 种密钥提取方法全部失败后，通过 LD_PRELOAD vtable hook 实现解密后视频流捕获的完整工程记录</description></item><item><title>学习拉马努金提高注意力的解题模式 - 谈谈基于DFA的Widevine L3 keybox量产技术</title><link>https://overkazaf.github.io/blogs/posts/widevine-l3-keybox-mass-production/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/widevine-l3-keybox-mass-production/</guid><description>通过差分故障攻击(DFA)提取Widevine L3白盒AES密钥，实现keybox离线量产的完整逆向工程记录</description></item><item><title>驯服六头蛇：驾驭希腊诸神 - 抖音六神签名算法的 unidbg 逆向全记录</title><link>https://overkazaf.github.io/blogs/posts/douyin-sixgod-metasec-unidbg-reverse-engineering/</link><pubDate>Sun, 29 Mar 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/douyin-sixgod-metasec-unidbg-reverse-engineering/</guid><description>通过 unidbg 仿真抖音 libmetasec_ml.so，突破 OLLVM+VM+JIT 三层防护，完整提取六神签名（X-Gorgon/X-Khronos/X-Argus/X-Ladon/X-Helios/X-Medusa）的逆向工程记录</description></item></channel></rss>