All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

methodologycrypto_testing.md

≈345 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Methodology: iOS Crypto Testing

Hook Points

Load scripts/crypto_hooks.js (Frida) — it traces CommonCrypto (CCCrypt, CCCryptorCreate), SecKeyCreateEncryptedData, and AES.GCM Swift wrappers, logging key material and mode selections.

Weakness Checklist

  • Hardcoded keys/IVs in binary strings (strings App.app/App | grep -iE 'key|iv').
  • ECB mode (CCCrypt option kCCOptionECBMode).
  • Static IV across messages (observe via hook log).
  • Insecure PRNG: rand(), arc4random() vs SecRandomCopyBytes — prefer the latter for key material.
  • Deprecated primitives: MD5, SHA-1 (for MAC/signature), DES, RC4, 3DES.
  • Missing authentication (CBC without HMAC → padding oracle).
  • Key derivation with low iteration count (PBKDF2 < 100k iterations in 2026).

Verifying a Key-Storage Flow

  1. Hook the constructor / first use of the cipher.
  2. Capture the key's origin — from Keychain (good), NSUserDefaults (bad), hardcoded (critical).
  3. Confirm key length, mode, IV uniqueness.

Custom / Home-rolled Crypto

Flag any class that combines XOR, rolls its own AES, or claims "proprietary encryption". Document and recommend CryptoKit or platform APIs.

TLS Fingerprint

If the app uses a custom TLS stack (for DRM/anti-MITM), note mTLS client certs (identity in Keychain) and how they are provisioned — often a static PKCS#12 bundled in the IPA.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest