<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ivan&apos;s Blog</title><description>Tech, Mobile, Hacking, Crypto(graphy), Security and Privacy.</description><link>https://ivrodriguez.com/</link><item><title>Dissecting the Malware Injected Into My Own Ghost Blog</title><link>https://ivrodriguez.com/dissecting-the-malware-injected-into-my-ghost-blog/</link><guid isPermaLink="true">https://ivrodriguez.com/dissecting-the-malware-injected-into-my-ghost-blog/</guid><description>tl;dr: I had not looked at my blog in months and found a malicious script injected into every post through the Ghost Admin API. What it does, and how I removed it.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Why embedding secrets in mobile apps is not a good idea</title><link>https://ivrodriguez.com/why-embedding-secrets-in-mobile-apps-is-not-a-good-idea/</link><guid isPermaLink="true">https://ivrodriguez.com/why-embedding-secrets-in-mobile-apps-is-not-a-good-idea/</guid><description>This is a somewhat complicated topic to cover, but I&apos;ll try to go into detail on why, generally, this is not a good idea and you should avoid embedding secrets…</description><pubDate>Sun, 15 Nov 2020 00:00:00 GMT</pubDate></item><item><title>About Canada&apos;s COVID Alert application</title><link>https://ivrodriguez.com/about-canadas-covid-alert-application/</link><guid isPermaLink="true">https://ivrodriguez.com/about-canadas-covid-alert-application/</guid><description>Disclaimer: First of all, I&apos;m not writing on behalf of any entities involved in the development of the COVID Alert application. This is my take as a software…</description><pubDate>Sun, 02 Aug 2020 00:00:00 GMT</pubDate></item><item><title>OPSEC tips for the general public</title><link>https://ivrodriguez.com/opsec-tips-for-the-general-public/</link><guid isPermaLink="true">https://ivrodriguez.com/opsec-tips-for-the-general-public/</guid><description>It&apos;s always a good idea to properly configure your computer and smartphone, know how to securely communicate with others and how to read, write and share…</description><pubDate>Mon, 01 Jun 2020 00:00:00 GMT</pubDate></item><item><title>Is the Guatemalan government asking citizens for their location to show them ads?</title><link>https://ivrodriguez.com/alerta-guate-analysis/</link><guid isPermaLink="true">https://ivrodriguez.com/alerta-guate-analysis/</guid><description>On Tuesday March 24th 2020, the president of Guatemala Alejandro Giammattei announced [https://twitter.com/DrGiammattei/status/1242828589524848643] that his…</description><pubDate>Thu, 26 Mar 2020 00:00:00 GMT</pubDate></item><item><title>Advice for Targets of Mobile Spyware</title><link>https://ivrodriguez.com/advice-for-targets-of-mobile-spyware/</link><guid isPermaLink="true">https://ivrodriguez.com/advice-for-targets-of-mobile-spyware/</guid><description>After publishing a blog post on spouseware [https://ivrodriguez.com/analyzing-ios-stalkerware-apps/], I started receiving many interesting messages about…</description><pubDate>Sat, 30 Nov 2019 00:00:00 GMT</pubDate></item><item><title>Introducing security.plist</title><link>https://ivrodriguez.com/introducing-security-plist/</link><guid isPermaLink="true">https://ivrodriguez.com/introducing-security-plist/</guid><description>tl;dr It&apos;s like security.txt [https://securitytxt.org/] but for iOS applications [https://securityplist.ivrodriguez.com/]. As probably you know by now, I spend…</description><pubDate>Thu, 21 Nov 2019 00:00:00 GMT</pubDate></item><item><title>What checkm8 means for stalkerware on iOS</title><link>https://ivrodriguez.com/what-checkm8-means-for-stalkareware-on-ios/</link><guid isPermaLink="true">https://ivrodriguez.com/what-checkm8-means-for-stalkareware-on-ios/</guid><description>On Friday, September 27th 2019 many of us on the mobile security community were surprised with the news of a SecureROM…</description><pubDate>Mon, 07 Oct 2019 00:00:00 GMT</pubDate></item><item><title>Decrypting iOS applications - iOS 12 Edition</title><link>https://ivrodriguez.com/decrypting-ios-applications-ios-12-edition/</link><guid isPermaLink="true">https://ivrodriguez.com/decrypting-ios-applications-ios-12-edition/</guid><description>As some of you may know, with the release of iOS 12.4 Apple accidentally reintroduced a vulnerability…</description><pubDate>Thu, 22 Aug 2019 00:00:00 GMT</pubDate></item><item><title>Analyzing iOS Stalkerware Applications</title><link>https://ivrodriguez.com/analyzing-ios-stalkerware-apps/</link><guid isPermaLink="true">https://ivrodriguez.com/analyzing-ios-stalkerware-apps/</guid><description>Stalkerware (a.k.a. Spouseware) applications are invasive applications that an individual installs on a target&apos;s device (usually their partner) to spy on them,…</description><pubDate>Mon, 22 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Investigating some subscription scam iOS apps</title><link>https://ivrodriguez.com/investigating-some-subscription-scam-ios-apps/</link><guid isPermaLink="true">https://ivrodriguez.com/investigating-some-subscription-scam-ios-apps/</guid><description>For some reason Apple allows &quot;subscription scam&quot; apps on the App Store. These are apps that are free to download and then ask you to subscribe right on launch.…</description><pubDate>Mon, 01 Jul 2019 00:00:00 GMT</pubDate></item><item><title>Created an &quot;age&quot; mobile client</title><link>https://ivrodriguez.com/created-an-age-mobile-client/</link><guid isPermaLink="true">https://ivrodriguez.com/created-an-age-mobile-client/</guid><description>A few days ago Filippo Valsorda [https://twitter.com/FiloSottile] twitted about a simple, secure and modern encryption tool that will hopefully substitute gpg…</description><pubDate>Mon, 20 May 2019 00:00:00 GMT</pubDate></item><item><title>Mobile App Sec Assemble</title><link>https://ivrodriguez.com/mobile-app-sec-assemble/</link><guid isPermaLink="true">https://ivrodriguez.com/mobile-app-sec-assemble/</guid><description>One of the reasons why I write blog posts about mobile app sec is for future me. I don&apos;t have a good memory so these posts help me refresh techniques and steps…</description><pubDate>Mon, 06 May 2019 00:00:00 GMT</pubDate></item><item><title>Who&apos;s collecting analytics data from mobile apps?</title><link>https://ivrodriguez.com/whos-collecting-analytics-from-mobile-apps/</link><guid isPermaLink="true">https://ivrodriguez.com/whos-collecting-analytics-from-mobile-apps/</guid><description>I have the absolute pleasure and honour of being one of the beta testers of the GuardianApp [https://guardianapp.com/]. In an upcoming post I&apos;ll be explaining…</description><pubDate>Sun, 28 Apr 2019 00:00:00 GMT</pubDate></item><item><title>Announcing my very own course: &quot;Reverse Engineer iOS Applications&quot; 📱</title><link>https://ivrodriguez.com/announcing-my-own-course-reverse-engineer-ios-applications/</link><guid isPermaLink="true">https://ivrodriguez.com/announcing-my-own-course-reverse-engineer-ios-applications/</guid><description>Big news! (or at least for me 😬) I&apos;ve decided to create my own take on an online course to show beginner and intermediate researchers how to reverse engineer…</description><pubDate>Mon, 01 Apr 2019 00:00:00 GMT</pubDate></item><item><title>How Facebook-Research app works</title><link>https://ivrodriguez.com/how-facebook-research-app-works/</link><guid isPermaLink="true">https://ivrodriguez.com/how-facebook-research-app-works/</guid><description>Last night I saw this tweet from Will Strafach [https://twitter.com/chronic]: After reading that article I just needed to reverse this iOS app and see how it…</description><pubDate>Wed, 30 Jan 2019 00:00:00 GMT</pubDate></item><item><title>Tips for Mobile Bug Bounty Hunting</title><link>https://ivrodriguez.com/tips-for-mobile-bug-bounty-hunting/</link><guid isPermaLink="true">https://ivrodriguez.com/tips-for-mobile-bug-bounty-hunting/</guid><description>My good friend Pete Yaworski [https://twitter.com/yaworsk] encouraged me to join the bug bounty scene for a long time before I decided to jump in and start…</description><pubDate>Thu, 20 Dec 2018 00:00:00 GMT</pubDate></item><item><title>Fix SSL Kill Switch2 not showing on Settings</title><link>https://ivrodriguez.com/fix-ssl-kill-switch2-not-showing-on-settings/</link><guid isPermaLink="true">https://ivrodriguez.com/fix-ssl-kill-switch2-not-showing-on-settings/</guid><description>If you landed on this blog post, it probably means you already know what SSL Kill Switch2 is. Therefore I&apos;m not going to explain what it is, but if you want to…</description><pubDate>Sat, 17 Nov 2018 00:00:00 GMT</pubDate></item><item><title>Racism and sexism are never funny</title><link>https://ivrodriguez.com/racism-is-never-funny/</link><guid isPermaLink="true">https://ivrodriguez.com/racism-is-never-funny/</guid><description>My blog is intended to be a hub of knowledge around Technology, Mobile &amp; Web Application Security, Cryptography, Coding and Hacking. However, this is a very…</description><pubDate>Fri, 16 Nov 2018 00:00:00 GMT</pubDate></item><item><title>What do Pointer Authentication Codes mean for iOS jailbreaking?</title><link>https://ivrodriguez.com/pointer-authentication-on-armv8-3/</link><guid isPermaLink="true">https://ivrodriguez.com/pointer-authentication-on-armv8-3/</guid><description>Yesterday, Sep 12th, Apple announced [https://www.youtube.com/watch?v=9m_K2Yg7wGQ] their next generation of iPhones. The iPhone X [s], X [s] Max and X [r] are…</description><pubDate>Thu, 13 Sep 2018 00:00:00 GMT</pubDate></item><item><title>Reverse Engineering iOS Apps - iOS 11 Edition (Part 2)</title><link>https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edition-part2/</link><guid isPermaLink="true">https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edition-part2/</guid><description>This is the second part of the &quot;Reverse Engineering iOS Apps - iOS 11 Edition&quot; series. In the first part of the series…</description><pubDate>Thu, 23 Aug 2018 00:00:00 GMT</pubDate></item><item><title>Formatting phone numbers in Swift</title><link>https://ivrodriguez.com/format-phone-numbers-in-swift/</link><guid isPermaLink="true">https://ivrodriguez.com/format-phone-numbers-in-swift/</guid><description>A simple code snippet to format 10 digit phone numbers in Swift 4.0, instead of including a big library, just implement a delegate function and a formatting…</description><pubDate>Sun, 11 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Saving your Github SSH Keys in a USB Drive</title><link>https://ivrodriguez.com/saving-your-github-ssh-keys-in-a-usb-drive/</link><guid isPermaLink="true">https://ivrodriguez.com/saving-your-github-ssh-keys-in-a-usb-drive/</guid><description>Github provides 2 main options for connecting (cloning, fetching, pulling, pushing) to repositories. HTTPS and SSH: HTTPS: This is the easiest way to clone a…</description><pubDate>Sat, 10 Mar 2018 00:00:00 GMT</pubDate></item><item><title>Reverse Engineering iOS Apps - iOS 11 Edition (Part 1)</title><link>https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edition-part1/</link><guid isPermaLink="true">https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edition-part1/</guid><description>Even though there are already many, many [https://www.google.com/search?q=reverse+engineering+ios+apps] blog posts, tutorials and even youtube videos…</description><pubDate>Wed, 28 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Proxy iOS 11 applications’ traffic</title><link>https://ivrodriguez.com/proxy-ios-apps-traffic/</link><guid isPermaLink="true">https://ivrodriguez.com/proxy-ios-apps-traffic/</guid><description>A big part of understanding how mobile apps work is to identify the endpoints they hit on the server side and the data they send and receive. In order to…</description><pubDate>Mon, 26 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Installing self-signed certificates on Android</title><link>https://ivrodriguez.com/installing-self-signed-certificates-on-android/</link><guid isPermaLink="true">https://ivrodriguez.com/installing-self-signed-certificates-on-android/</guid><description>One of the best trends these days is the shift to encrypted Internet traffic, aka Transport Layer Security or TLS, and mobile apps are not the exception, often…</description><pubDate>Sat, 24 Feb 2018 00:00:00 GMT</pubDate></item><item><title>Fix Cydia Impactor crypto-osx.cpp:97 error</title><link>https://ivrodriguez.com/fix-cydia-impactor-crypto-osx-cpp-97-error/</link><guid isPermaLink="true">https://ivrodriguez.com/fix-cydia-impactor-crypto-osx-cpp-97-error/</guid><description>If you upgraded to macOS Hight Sierra 10.13.x changes are Cydia Impactor [http://www.cydiaimpactor.com/] is giving you this error when trying to install an…</description><pubDate>Sat, 13 Jan 2018 00:00:00 GMT</pubDate></item><item><title>Installing Dropbear SSH on iOS 10.3.3</title><link>https://ivrodriguez.com/installing-dropbear-ssh-on-ios-10-3-3/</link><guid isPermaLink="true">https://ivrodriguez.com/installing-dropbear-ssh-on-ios-10-3-3/</guid><description>In December last year, @thimstar [https://twitter.com/tihmstar] and @S1guza [https://twitter.com/s1guza] released H3lix [https://h3lix.tihmstar.net/] a…</description><pubDate>Thu, 04 Jan 2018 00:00:00 GMT</pubDate></item><item><title>Reversing one thousand binaries</title><link>https://ivrodriguez.com/reversing-one-thousand-binaries/</link><guid isPermaLink="true">https://ivrodriguez.com/reversing-one-thousand-binaries/</guid><description>This past week (Nov 3rd) I attended the Hackfest CTF in Quebec city, QC. This was my second CTF and was the fist time I ever found a flag. This is how I found…</description><pubDate>Sun, 05 Nov 2017 00:00:00 GMT</pubDate></item><item><title>The most innovative “thing” I’ve done (so far)</title><link>https://ivrodriguez.com/the-most-innovative-thing-ive-done-so-far/</link><guid isPermaLink="true">https://ivrodriguez.com/the-most-innovative-thing-ive-done-so-far/</guid><description>The context I’m a software engineer and really enjoy using technology, but I love using technology to solve problems and make people’s lives better. For the…</description><pubDate>Sun, 26 Jun 2016 00:00:00 GMT</pubDate></item></channel></rss>