All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

methodologyauth_testing.md

≈407 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Methodology: iOS Authentication Testing

See also: workflows/auth_testing.md for the runbook.

Axes of Review

  1. Local gate — PIN, pattern, biometric. Can Frida flip the result? If yes, does it actually grant access to protected data or just UI?
  2. Server gate — Does the server independently validate each sensitive request? Or does it trust a "logged in" flag?
  3. Session management — Token lifetime, rotation on password change, logout invalidates server-side, device binding.
  4. Credential storage — Keychain with appropriate accessibility + SecAccessControl?

Biometric Hook Points

  • -[LAContext canEvaluatePolicy:error:]
  • -[LAContext evaluatePolicy:localizedReason:reply:]
  • -[LAContext evaluateAccessControl:operation:localizedReason:reply:] Return YES / invoke reply with success = bypass unless Keychain gate also requires actual biometric for item retrieval (then the key won't decrypt and app fails downstream — positive signal of strong design).

OAuth / SSO

  • Capture auth redirect flow in Burp.
  • Check PKCE (code_challenge, code_challenge_method=S256).
  • Check redirect URI allowlist (app-scheme:// URI).
  • Attempt scheme hijack: install a sibling app claiming the same scheme.

WebView Auth

  • WKWebView auth forms: inspect evaluateJavaScript: usage, cookie sharing.
  • SFSafariViewController is more isolated; flag use of WKWebView for SSO as weaker.

Rate Limiting / Lockout

Server-side — out of MASTG client scope, but note behaviour when 20 wrong PINs are attempted locally (app-level lockout) and whether a reinstall resets the counter.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest