Methodology: iOS Network Testing
Proxy Setup
- Burp on host, listener
0.0.0.0:8080, invisible proxying off for first pass. - On device: Settings > Wi-Fi > (i) > Configure Proxy > Manual >
<host>:8080. - Export Burp CA (DER), host it via
python3 -m http.server, download on Safari, install profile. - Settings > General > About > Certificate Trust Settings > enable Burp root.
Validating Interception
# From the device's Safari: hit https://example.com — if pinning not in play you see it in Burp.
# If the target app's traffic is absent, SSL pinning is likely — run workflows/ssl_pinning_bypass.md.Traffic Classification
- HTTP/1.1 & HTTP/2 over TLS → Burp handles natively.
- WebSockets → visible under Proxy > WebSockets history.
- gRPC over HTTP/2 → Burp 2024+ decodes; use the gRPC extension.
- QUIC/HTTP3 → Burp does not intercept. Block UDP/443 at the proxy host to force TCP fallback.
ATS (App Transport Security) Review
plutil -p App.app/Info.plist | grep -A20 NSAppTransportSecurityFindings: NSAllowsArbitraryLoads=YES, per-domain NSExceptionAllowsInsecureHTTPLoads=YES, low NSExceptionMinimumTLSVersion.
Certificate Pinning Inventory
NSURLSessiondelegateURLSession:didReceiveChallenge:completionHandler:.- AFNetworking
AFSecurityPolicy. - TrustKit (
TSKPinningValidator). - Alamofire
ServerTrustManager. - Raw BoringSSL / OpenSSL inside a static lib.
Find via
class-dump+grep -iE 'trust|pin'.
Attack Paths
- Mixed content in WKWebView (HTTP subresources with ATS exception).
- URL scheme-based open redirect.
- Missing HSTS on API responses.
- Tokens in query string (logged in CDN/proxy).