All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

methodologydata_storage.md

≈598 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Methodology: iOS Data Storage

Storage Surfaces

Location Encrypted by default? Notes
Keychain Yes (varies by accessibility flag) See workflows/keychain_extraction.md
NSUserDefaults → Library/Preferences/*.plist File-level (Data Protection class) Commonly abused for tokens
Documents/ Data Protection class Backed up to iCloud by default
Library/Caches/ Data Protection class Not backed up, but survives reboot
tmp/ Data Protection class Cleared opportunistically
SQLite / Realm / Core Data File-level only Data inside is plaintext
iOS Pasteboard No Cross-app clipboard
Snapshot cache Library/Caches/Snapshots/ No App switcher screenshots

Data Protection Classes

# On device (jailbroken):
find /var/mobile/Containers/Data/Application/<UUID> -type f -exec ls -l@ {} \; | grep -i protection

Expected for sensitive files: NSFileProtectionComplete. Vulnerable: NSFileProtectionNone, NSFileProtectionCompleteUntilFirstUserAuthentication (survives lock).

Objection Dumps

> ios nsuserdefaults get
> ios cookies get
> ios nsurlcredentialstorage dump
> ios plist cat <path>
> sqlite connect <path>          # then .tables / SELECT
> file download <remote> <local>

Snapshot Leak

Background the app with sensitive data on screen. Then:

ssh root@device "ls /var/mobile/Containers/Data/Application/<UUID>/Library/Caches/Snapshots/"

If the snapshot shows sensitive data → missing applicationWillResignActive: blur.

Pasteboard Leak

> ios pasteboard monitor

Or hook -[UIPasteboard setString:] / -[UIPasteboard setItems:] with a small Frida script (template in references/frida_ios_snippets.md). Flag if passwords/tokens land on the general pasteboard.

Logs

idevicesyslog | grep <bundle_id>

Flag tokens, PII, stack traces in NSLog output on release builds.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest