iOS Application Penetration Testing
iOS applications are distributed as IPA packages and generally require a macOS environment and tooling such as Xcode and Frida to test. This section covers building an iOS testing environment, extracting the application package, checking for debug symbols, and instrumenting apps on non-jailbroken devices.
Setup and Preparation
Testing iOS applications generally requires a macOS environment for Xcode and the associated command-line tooling, plus a way to obtain the application’s IPA package.
Install macOS on VMware
If you do not have Apple hardware, macOS can be run in a VMware virtual machine.
# Setting up macOS:https://www.youtube.com/watch?v=g8iQMlMuegwhttps://www.makeuseof.com/tag/macos-windows-10-virtual-machine/Extract an IPA from the App Store
iMazing can download and export an installed app as an .ipa file.
https://imazing.com/
# Using iMazing1. Open iMazing on your PC.2. Plug in your iPhone or iPad.3. Go to Apps -> Manage Apps -> Library.4. Find the app you want to download and click the cloud icon next to it.5. Once downloaded, right-click the app and choose "Export .IPA".Static Analysis
Checking for Debug Symbols
Unzip the .ipa and run objdump against the main application executable to check for debug symbols.
https://www.virtuesecurity.com/kb/ios-frida-objection-pentesting-cheat-sheet/
# Looking for debug symbols# Unzip the .ipa file and run objdump against the iOS main application (executable)objdump --syms Example.app/ExampleRuntime Analysis with Objection and Frida
Frida and Objection can instrument iOS apps, including on non-jailbroken devices after the IPA has been patched and re-signed.
Xcode iPhone Simulator
# List available simulatorsxcrun simctl list # Look for the one that says "Booted"Frida on Non-Jailbroken iOS Devices
https://medium.com/@codeWithAhmedAli/how-to-use-frida-on-non-jailbreak-ios-devices-ea8d89c07369
# 1. Install Python.brew install python
# 2. Install Frida tools.pip3 install frida-tools
# 3. Install the Xcode Command Line Tools.xcode-select --install
# 4. Install Objection (a runtime mobile exploration toolkit).pip3 install objection
# 5. Clone and build insert_dylib, which helps inject Frida into the app.git clone https://github.com/Tyilo/insert_dylibcd insert_dylib/xcodebuildcp build/Release/insert_dylib /usr/local/bin/insert_dylib # Use your own user path
# 6. Place your .ipa file in a separate folder.
# 7. Obtain a signing identity to re-sign the IPA with Frida embedded.security find-identity -p codesigning -v
# 8. Run any simple app on your device to generate an embedded.mobileprovision file,# which is needed for the re-signing process.
# 9. Patch the IPA using Objection (re-sign with Frida embedded).objection patchipa --source TestApp.ipa --codesign-signature ABCDEFG# Replace ABCDEFG with your signing identity key. If you hit issues, ensure these# Python packages are installed:pip3 install clickpip3 install blackpip3 install setuptools
# 10. Install applesign, which helps re-sign the IPA.npm install -g applesign
# 11. Unzip the signed IPA.unzip TestApp-frida-codesigned.ipa
# 12. Deploy the app to your device using ios-deploy (connect the device via USB).ios-deploy --bundle Payload/TestApp.app -W -d


