All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

referencestroubleshooting.md

≈420 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting

Frida

"Unable to find application"

ideviceinstaller -l | grep -i <name>
frida-ps -Uai
frida -U -f <exact.bundle.id> --no-pause

"Frida server not running"

ssh root@<device>
/usr/sbin/frida-server &          # or: launchctl load /Library/LaunchDaemons/re.frida.server.plist
# Verify from host:
frida-ps -U

"Failed to spawn: unable to access process"

  • Non-jailbroken: repackage IPA with Frida Gadget: objection patchipa --source app.ipa --codesign-signature "Apple Development: you"
  • Mount developer disk image: ideviceimagemounter /path/DeveloperDiskImage.dmg.

Frida crashes target on spawn

  • Try --realm emulated (for apps with Swift-concurrency heavy init).
  • Load a small anti-debug Frida snippet first that overrides ptrace to return 0 (see references/frida_ios_snippets.md).
  • Use attach (not spawn) once app is foregrounded.

SSL Pinning — Universal Bypass Fails

  1. Enumerate: ios hooking search classes Trust|SSL|Certificate|Pin.
  2. class-dump + grep -iE 'pin|trust' the binary.
  3. Write a targeted hook for the found class/method.
  4. Rare: statically linked BoringSSL — hook C symbols (SSL_CTX_set_verify).

Jailbreak Detection

  1. > ios jailbreak disable (Objection).
  2. Install Liberty Lite or Shadow; add app to hide list.
  3. frida -l scripts/jailbreak_bypass.js.
  4. Custom hook of the specific method in the app's SecurityChecker class.

Proxy Not Intercepting App Traffic

  • Confirm Wi-Fi proxy set and Burp CA trusted in Certificate Trust Settings.
  • QUIC/HTTP3 → block UDP/443.
  • App uses IP literals to bypass DNS → DNS override or iptables on proxy host.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest