<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Muhammad Alief</title><description>Muhammad Alief is an Android developer and mobile security engineer. Kotlin, clean architecture, reverse engineering and CTF write-ups.</description><link>https://www.alieflab.com/</link><language>en-us</language><lastBuildDate>Sun, 04 Oct 2026 03:31:58 GMT</lastBuildDate><atom:link href="https://www.alieflab.com/rss.xml" rel="self" type="application/rss+xml"/><generator>Astro vAstro v5.14.5</generator><item><title>Recovering Deleted Git History: Restoring a Removed Commit to Reveal Sensitive Data</title><link>https://www.alieflab.com/blog/recover-deleted-git-commit-forensics/</link><guid isPermaLink="true">https://www.alieflab.com/blog/recover-deleted-git-commit-forensics/</guid><description>A hands-on demonstration of forensic Git analysis showing how a removed commit containing sensitive information was recovered using commit history checkout during a CTF challenge.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Forensic</category><category>forensic</category><category>git</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Extracting Hidden Evidence: Recovering Embedded Base64 Data from Image EXIF Metadata</title><link>https://www.alieflab.com/blog/forensic-exif-hidden-base64/</link><guid isPermaLink="true">https://www.alieflab.com/blog/forensic-exif-hidden-base64/</guid><description>Identifying hidden Base64 strings inside EXIF metadata and decoding them to recover a concealed flag — a practical forensic analysis approach used in CTF challenges.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Forensic</category><category>forensic</category><category>exif</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Layered Encryption Breakdown: Decoding Nested Base64 and ROT13 to Reveal Hidden Flag</title><link>https://www.alieflab.com/blog/layered-base64-rot13-decryption/</link><guid isPermaLink="true">https://www.alieflab.com/blog/layered-base64-rot13-decryption/</guid><description>Step-by-step analysis of a multi-layer encoding challenge where nested Base64 and ROT13 shifting were used to obscure a flag — demonstrating practical CTF cryptography skills.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Cryptography</category><category>cryptography</category><category>caesar</category><category>base64</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Tracing Malware Execution via Windows Event Viewer: Investigating Process Activity to Reveal Hidden Payload</title><link>https://www.alieflab.com/blog/windows-event-viewer-malware-behavior-log-analysis/</link><guid isPermaLink="true">https://www.alieflab.com/blog/windows-event-viewer-malware-behavior-log-analysis/</guid><description>A malware investigation using Windows Event Viewer logs uncovered the infection path, identified the malicious process, and decoded a Base64-encoded secret embedded in the execution chain.</description><pubDate>Wed, 02 Apr 2025 00:00:00 GMT</pubDate><category>Malware Analysis</category><category>event-viewer</category><category>malware</category><category>challenge</category><category>pico-ctf</category><category>windows</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Malware Analysis of FakeGPT Browser Extension: Static Code Review for Blue Team Training</title><link>https://www.alieflab.com/blog/malware-analysis-fakegpt-browser-extension-static-review/</link><guid isPermaLink="true">https://www.alieflab.com/blog/malware-analysis-fakegpt-browser-extension-static-review/</guid><description>A structured malware analysis exercise on a malicious FakeGPT browser extension. Static code inspection was performed to answer investigative questions and identify behaviors relevant to Blue Team defense.</description><pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate><category>Malware Analysis</category><category>reverse-engineering</category><category>browser-extension</category><category>malware</category><category>challenge</category><category>cyber-defender</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Manually Patching Smali Code: Fixing Misrouted Function Calls to Unlock Hidden Flag in Android APK</title><link>https://www.alieflab.com/blog/manual-smali-patching-android-function-redirect/</link><guid isPermaLink="true">https://www.alieflab.com/blog/manual-smali-patching-android-function-redirect/</guid><description>A manual Smali patch was applied to an Android APK after static analysis revealed that the flag function was never called. Redirecting the function call and rebuilding the app exposed the hidden flag.</description><pubDate>Wed, 31 Jul 2024 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>manual</category><category>smali-patching</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Bypassing Logic Flow via Smali Patching: Redirecting Function Calls to Reveal Hidden Flag in Android APK</title><link>https://www.alieflab.com/blog/android-smali-patching-redirect-function-call/</link><guid isPermaLink="true">https://www.alieflab.com/blog/android-smali-patching-redirect-function-call/</guid><description>A static analysis of an Android APK uncovered misleading password logic designed to hide the real flag function. By modifying the Smali code to patch the function call, the correct method was executed and the flag recovered.</description><pubDate>Wed, 31 Jul 2024 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>logic-bypass</category><category>smali-patching</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Breaking Weak Code Protection: Decoding Obfuscated Password Logic in Android Application</title><link>https://www.alieflab.com/blog/android-weak-obfuscation-password-decoding/</link><guid isPermaLink="true">https://www.alieflab.com/blog/android-weak-obfuscation-password-decoding/</guid><description>Static analysis of an Android app revealed a weak password protection mechanism based on simple arithmetic and string manipulation. Manually decoding the logic exposed the correct password and retrieved the flag.</description><pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>android</category><category>weak-code</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Extracting Hard-Coded Secrets from strings.xml: Uncovering Hidden Keys via Android Static Analysis</title><link>https://www.alieflab.com/blog/android-strings-xml-hardcoded-secret-static-analysis/</link><guid isPermaLink="true">https://www.alieflab.com/blog/android-strings-xml-hardcoded-secret-static-analysis/</guid><description>Reverse engineering an Android app revealed a secret key stored in strings.xml. By tracing input validation and comparing the stored value, the hidden flag was successfully exposed.</description><pubDate>Mon, 29 Jul 2024 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>android</category><category>strings.xml</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Exploiting Insecure Logging: Retrieving Sensitive Data from Android Logcat During Runtime Analysis</title><link>https://www.alieflab.com/blog/android-logcat-sensitive-data-exposure/</link><guid isPermaLink="true">https://www.alieflab.com/blog/android-logcat-sensitive-data-exposure/</guid><description>Runtime analysis of an Android app revealed sensitive data exposed through Logcat logs. By triggering the native function and monitoring logs, the hidden flag was retrieved.</description><pubDate>Sun, 28 Jul 2024 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>android</category><category>logcat</category><category>challenge</category><category>pico-ctf</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item><item><title>Static Analysis of React Native APK: Extracting Hard-Coded API Tokens Through Bundle Inspection</title><link>https://www.alieflab.com/blog/react-native-apk-static-analysis-exposed-api-token/</link><guid isPermaLink="true">https://www.alieflab.com/blog/react-native-apk-static-analysis-exposed-api-token/</guid><description>A walkthrough of reversing a React Native APK using JADX and bundle inspection to expose a hard-coded API token, demonstrating practical static analysis skills in mobile security.</description><pubDate>Wed, 04 May 2022 00:00:00 GMT</pubDate><category>Mobile Security</category><category>reverse-engineering</category><category>react-native</category><category>apk</category><category>challenge</category><category>nahamcon</category><author>malief.dev@gmail.com (Muhammad Alief)</author></item></channel></rss>