All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

workflowsauth_testing.md

≈446 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Authentication & Biometric Testing

Enumerate Auth Surface

class-dump -H App.app/App -o headers/
grep -RIn -iE 'login|auth|oauth|jwt|token|biometr|faceid|touchid|LAContext' headers/
objection -g <bundle_id> explore
> ios hooking search classes Auth
> ios hooking search classes Login
> ios hooking search classes LAContext

Hook Biometric Gate

> ios hooking watch class LAContext
> ios hooking watch method "-[LAContext evaluatePolicy:localizedReason:reply:]" --dump-args --dump-return

Or force success:

frida -U <bundle_id> -l scripts/biometric_bypass.js

Critical Server-Side Check

A local biometric bypass only matters if the server trusts the client. For each sensitive action:

  1. Bypass biometric locally (Frida).
  2. Attempt the action.
  3. If the server completes the action without an attestation / signed challenge tied to the biometric unlock → finding (broken auth).

Token & Session Tests

  • Capture JWT/session in Burp; decode (jwt.io or jq).
  • Test token lifetime, rotation on privilege change, revocation on logout.
  • Check refresh token storage (should be Keychain with kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly).
  • Replay captured tokens from a different device → should fail if device binding is enforced.

Multimodal — UI-driven Flow

Use Mobile MCP to drive the login screen, capture the "Face ID prompt" screenshot pre-bypass and post-bypass as evidence (evidence.screenshot).

Common Findings

  • Biometric bypass grants access to protected screens (MASVS-AUTH-2).
  • Refresh tokens stored in NSUserDefaults (MASVS-STORAGE-1).
  • Session does not rotate on password change (MASVS-AUTH-3).
  • No rate limit on login endpoint (server-side; out of MASTG scope — note in report).

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest