All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

workflowsjailbreak_detection_bypass.md

≈417 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Jailbreak Detection Bypass

Use when an app exits, shows a warning, or disables features on jailbroken devices.

Detection Vectors to Defeat

  • File existence: /Applications/Cydia.app, /bin/bash, /usr/sbin/sshd, /etc/apt, /private/var/lib/apt.
  • URL scheme probe: cydia://, sileo://, zbra://.
  • Writable path checks: /private/jailbreak.txt.
  • Dynamic library enumeration: _dyld_image_count, _dyld_get_image_name hunting for MobileSubstrate, frida, cynject.
  • fork() / ptrace returning unexpectedly.
  • Sandbox escape via stat on /private, /.

Bypass Options (try in order)

  1. Objection: > ios jailbreak disable
  2. Frida: frida -U -f <bundle_id> -l scripts/jailbreak_bypass.js --no-pause
  3. Cydia tweaks: Liberty Lite, Shadow, A-Bypass (install + add app to hide list).
  4. Custom hook of the specific detection method discovered via class-dump.

Identifying Custom Detection

class-dump -H App.app/App -o headers/
grep -RIn -iE 'jailbreak|cydia|isJailbroken|checkRoot' headers/

Then in Frida, intercept the found selector:

var cls = ObjC.classes.SecurityChecker;
Interceptor.attach(cls['- isJailbroken'].implementation, {
  onLeave: function (retval) { retval.replace(0); }
});

Screen-based Prompt Confirmation

Apps sometimes show a "Jailbreak detected" modal. Capture it with Mobile MCP to prove trigger, then re-run with bypass to confirm absence.

Anti-Anti-Debug

If ptrace(PT_DENY_ATTACH) trips on spawn, hook ptrace to return 0 and sysctl to scrub P_TRACED from the kinfo_proc flags (snippet in references/frida_ios_snippets.md); spawn with --no-pause.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest