All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

workflowsssl_pinning_bypass.md

≈424 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: SSL Pinning Bypass

Triage

  1. Try universal Objection bypass first.
  2. If traffic still fails to decrypt in Burp, identify the pinning library.
  3. Write/adapt a targeted Frida hook.

Method 1 — Objection Universal

objection -g <bundle_id> explore
> ios sslpinning disable

Method 2 — Frida Universal Script

frida -U -f <bundle_id> -l scripts/ssl_pinning_bypass.js --no-pause

Covers: NSURLSession, SecTrustEvaluate*, AFNetworking AFSecurityPolicy, TrustKit, Alamofire ServerTrustManager.

Method 3 — Identify Custom Pinning

objection -g <bundle_id> explore
> ios hooking search classes Trust
> ios hooking search classes SSL
> ios hooking search classes Pin
> ios hooking search methods pinn
class-dump -H App.app/App -o headers/
grep -RIn -iE 'pin|trust|certificate' headers/ | head -50

Then write a targeted hook that overrides the policy's evaluation to return YES / calls the completion handler with NSURLSessionAuthChallengeUseCredential.

Method 4 — ATS Bypass (dev builds only)

Add to Info.plist: NSAppTransportSecurity.NSAllowsArbitraryLoads = YES. Not applicable to installed App Store binaries.

Verification

curl -x http://<burp_host>:8080 --cacert burp.pem https://api.target.tld/health   # sanity
# Then drive the app and confirm Burp HTTP history fills with TLS-decrypted traffic.

Common Failure Modes

  • Pinning happens in a statically linked BoringSSL — hook SSL_CTX_set_verify / SSL_get_verify_result.
  • Certificate Transparency enforcement — hook SecTrustEvaluateWithError.
  • App uses QUIC/HTTP3 — Burp cannot intercept; force HTTP/2 via proxy or block UDP/443.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest