All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

workflowscomplete_assessment.md

≈550 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Complete iOS Application Assessment

End-to-end assessment aligned to OWASP MASTG. Expect 1-3 days per app.

Phase 1 — Recon (parallelizable)

ideviceinstaller -l                              # enumerate installed apps
idevice_id -l                                    # UDID
ideviceinfo | grep -iE 'ProductVersion|ProductType'
objection -g <bundle_id> explore
> ios info binary
> ios bundles list_frameworks
> env                                            # data/bundle paths

Phase 2 — Acquire & Decrypt IPA

# Jailbroken pull:
ssh root@<device> "cp -r /var/containers/Bundle/Application/<UUID>/App.app /tmp/"
scp -r root@<device>:/tmp/App.app ./

# App Store encrypted binary: decrypt
frida-ios-dump <bundle_id>           # or: python3 dump.py <bundle_id>
# Verify: otool -l App.app/App | grep -A4 LC_ENCRYPTION_INFO  (cryptid 0 = decrypted)

Phase 3 — Static Analysis (parallelize the three tools)

class-dump -H App.app/App -o headers/        &
otool -L App.app/App                         &
strings -a App.app/App | grep -iE 'api|key|secret|password|token|bearer' &
wait
plutil -p App.app/Info.plist                 # URL schemes, ATS, entitlements
codesign -d --entitlements :- App.app

Phase 4 — Bypass Protections (sequential; each hook must land before next)

objection -g <bundle_id> explore --startup-command 'ios sslpinning disable'
> ios jailbreak disable
> ios jailbreak simulate
# Or Frida:
frida -U -f <bundle_id> -l scripts/ssl_pinning_bypass.js -l scripts/jailbreak_bypass.js --no-pause

Phase 5 — Dynamic Analysis

> ios keychain dump --json > keychain.json
> ios nsuserdefaults get
> ios cookies get
> ios nsurlcredentialstorage dump
> ios hooking watch class AuthManager
> ios hooking watch method "-[AuthManager authenticate:]" --dump-args --dump-return

Phase 6 — Network Testing

Configure device Wi-Fi HTTP proxy to Burp host; install Burp CA via Safari; trust in Settings > General > About > Certificate Trust Settings. Validate interception then replay/modify.

Phase 7 — Reporting

Emit findings per schemas/finding.json. Tag each with mastg_id and MASVS category.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest