Workflow: Authentication & Biometric Testing
Enumerate Auth Surface
class-dump -H App.app/App -o headers/
grep -RIn -iE 'login|auth|oauth|jwt|token|biometr|faceid|touchid|LAContext' headers/
objection -g <bundle_id> explore
> ios hooking search classes Auth
> ios hooking search classes Login
> ios hooking search classes LAContextHook Biometric Gate
> ios hooking watch class LAContext
> ios hooking watch method "-[LAContext evaluatePolicy:localizedReason:reply:]" --dump-args --dump-returnOr force success:
frida -U <bundle_id> -l scripts/biometric_bypass.jsCritical Server-Side Check
A local biometric bypass only matters if the server trusts the client. For each sensitive action:
- Bypass biometric locally (Frida).
- Attempt the action.
- If the server completes the action without an attestation / signed challenge tied to the biometric unlock → finding (broken auth).
Token & Session Tests
- Capture JWT/session in Burp; decode (
jwt.ioorjq). - Test token lifetime, rotation on privilege change, revocation on logout.
- Check refresh token storage (should be Keychain with
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly). - Replay captured tokens from a different device → should fail if device binding is enforced.
Multimodal — UI-driven Flow
Use Mobile MCP to drive the login screen, capture the "Face ID prompt" screenshot pre-bypass and post-bypass as evidence (evidence.screenshot).
Common Findings
- Biometric bypass grants access to protected screens (MASVS-AUTH-2).
- Refresh tokens stored in
NSUserDefaults(MASVS-STORAGE-1). - Session does not rotate on password change (MASVS-AUTH-3).
- No rate limit on login endpoint (server-side; out of MASTG scope — note in report).