black electronics

iOS

iOS Application Penetration Testing

iOS Application Penetration Testing

iOS applications are distributed as IPA packages and generally require a macOS environment and tooling such as Xcode and Frida to test. This section covers building an iOS testing environment, extracting the application package, checking for debug symbols, and instrumenting apps on non-jailbroken devices.

Setup and Preparation

Testing iOS applications generally requires a macOS environment for Xcode and the associated command-line tooling, plus a way to obtain the application’s IPA package.

Install macOS on VMware

If you do not have Apple hardware, macOS can be run in a VMware virtual machine.

Terminal window
# Setting up macOS:
https://www.youtube.com/watch?v=g8iQMlMuegw
https://www.makeuseof.com/tag/macos-windows-10-virtual-machine/

Extract an IPA from the App Store

iMazing can download and export an installed app as an .ipa file.

Terminal window
https://imazing.com/
# Using iMazing
1. Open iMazing on your PC.
2. Plug in your iPhone or iPad.
3. Go to Apps -> Manage Apps -> Library.
4. Find the app you want to download and click the cloud icon next to it.
5. Once downloaded, right-click the app and choose "Export .IPA".

Static Analysis

Checking for Debug Symbols

Unzip the .ipa and run objdump against the main application executable to check for debug symbols.

Terminal window
https://www.virtuesecurity.com/kb/ios-frida-objection-pentesting-cheat-sheet/
# Looking for debug symbols
# Unzip the .ipa file and run objdump against the iOS main application (executable)
objdump --syms Example.app/Example

Runtime Analysis with Objection and Frida

Frida and Objection can instrument iOS apps, including on non-jailbroken devices after the IPA has been patched and re-signed.

Xcode iPhone Simulator

Terminal window
# List available simulators
xcrun simctl list # Look for the one that says "Booted"

Frida on Non-Jailbroken iOS Devices

Terminal window
https://medium.com/@codeWithAhmedAli/how-to-use-frida-on-non-jailbreak-ios-devices-ea8d89c07369
# 1. Install Python.
brew install python
# 2. Install Frida tools.
pip3 install frida-tools
# 3. Install the Xcode Command Line Tools.
xcode-select --install
# 4. Install Objection (a runtime mobile exploration toolkit).
pip3 install objection
# 5. Clone and build insert_dylib, which helps inject Frida into the app.
git clone https://github.com/Tyilo/insert_dylib
cd insert_dylib/
xcodebuild
cp build/Release/insert_dylib /usr/local/bin/insert_dylib # Use your own user path
# 6. Place your .ipa file in a separate folder.
# 7. Obtain a signing identity to re-sign the IPA with Frida embedded.
security find-identity -p codesigning -v
# 8. Run any simple app on your device to generate an embedded.mobileprovision file,
# which is needed for the re-signing process.
# 9. Patch the IPA using Objection (re-sign with Frida embedded).
objection patchipa --source TestApp.ipa --codesign-signature ABCDEFG
# Replace ABCDEFG with your signing identity key. If you hit issues, ensure these
# Python packages are installed:
pip3 install click
pip3 install black
pip3 install setuptools
# 10. Install applesign, which helps re-sign the IPA.
npm install -g applesign
# 11. Unzip the signed IPA.
unzip TestApp-frida-codesigned.ipa
# 12. Deploy the app to your device using ios-deploy (connect the device via USB).
ios-deploy --bundle Payload/TestApp.app -W -d
Useful LinksPentest PayloadsCheat Sheets