4 ms·
Thanks for submitting the article! Let me know if anyone has any questions. If you are wondering how Apple obfuscate its software, the answer is simple: they bu
by nicolodev 3y ago
Thanks for submitting the article! Let me know if anyone has any questions. If you are wondering how Apple obfuscate its software, the answer is simple: they built some extensions for LLVM that applies code transformation directly to LLVM IR. LLVM IR is an intermediate language to represent the code that will be copied in binary.
- jchw 3y agoThanks for taking the time to write about your reverse engineering experience. I'm more of a programmer than a reverse engineer, but I do like to dabble in RE and analysis and dealing with obfuscation and techniques like virtualization is always quite a challenge. There's probably a lot of learning material out there, but it feels difficult to digest at times, so articles like these are always helpful for getting some perspective on how these things work out in practice, and getting a feel for some of the approaches you can use when you run into a roadblock. Definitely makes me want to go mess around with some binary analysis after work.
- nicolodev 3y agoThanks for your comment. This article was written in one go, and it could be way better than the actual state. However I do appreciate that you mean to consider my article as a nice example on how things work out in practice. Being a programmer and knowing a little bit of reverse engineering is important (well, I'm still a programmer too!). If you have any questions, please let me know. Regarding the difficulty of learning material, I can feel you. It was the same for me when I started (I have a lot of stuff to dig into!), and it's still. Academy papers might be difficult to understand, but once you comprehend the formalisms it'll be easier. For sure, understanding the formal formulas is another challenge that I haven't resolved yet.
- drdrey 3y agoGreat write-up! I was one of the Apple engineers who implemented some of these obfuscations. Fun to see an outside perspective on your work.
- nicolodev 3y agoThanks a lot!!! I can't believe I meet you on HN, great work so far
- motrm 3y ago> We use IDA for convenience in this article, although we must be especially careful when importing the binary into other tools (we will explain why at the end of the article) Forgive me if I missed this being explained - I was curious what the reasoning for this was and I didn't see it! Could you elaborate? :)
- nicolodev 3y agoOps! Forgot to write about it (otherwise it would be so long). I did not mention the tools, but I was mainly referring to Hopper Decompiler/Disassembler (definitely no no for me). Altough it seemed the natural choice for reverse engineering macOS applications and daemons, it failed disastrousely on reverse engineering fairplayd. This is where obfuscation is really good at: feeling pain. Hopper tried to disassemblate the binary but still no luck (there was an error due to some bogus instructions referred by a dead branch). I'm seeing improvements for Hopper release by release, but there were some regressions that I noticed.. I tried to import it into Ghidra and it missed some informations during the pass of stack analysis. At the end it was a mess result to read, so I ended it up with IDA (free because I'm a student). Binary ninja also needs some license, I'm trying to afford it.
- motrm 3y agoSo mainly just Ghidra & Hopper were successfully tripped up by fairplayd - thanks for the explanation! Great article overall, thanks for taking the time to write it up.
- nicolodev 3y agoGhidra was somehow usable, I got several crashes with Hopper. One question for more expert people than me: does Hopper employ any telemetry inside its demo version? Some issues I discovered were fixed in two days and I did not report them.