iOS Pentesting
iOS is more closed than Android: sandboxing is strict, the filesystem is more protected, and without a jailbreak access is limited. Apps ship as an IPA (a ZIP with the Mach-O binary encrypted by the App Store, resources, and Info.plist). Still, with a jailbroken device (or no-jailbreak techniques) and Frida, you can inspect, instrument, and audit an iOS app following the same MASVS.
The IPA and its pieces
Section titled “The IPA and its pieces”IPA = ZIP with Payload/App.app/: <Mach-O binary> the executable (FairPlay-encrypted if from the App Store) Info.plist configuration, URL schemes (deeplinks), ATS, permissions embedded.mobileprovision provisioning profile _CodeSignature/ signature resources (.plist, .db, assets)The FairPlay encryption challenge
Section titled “The FairPlay encryption challenge”App Store apps come encrypted; for static analysis of the binary you must decrypt it first (dump from memory on the device):
# on a jailbroken device, dump the decrypted binaryfrida-ios-dump # extracts the decrypted IPA# or Clutch / bagbak# then static analysis of the Mach-OTesting environment
Section titled “Testing environment”# with jailbreak (full access)checkra1n / palera1n / unc0ver depending on the iOS version# SSH access to the device, Cydia/Sileo for tools# without jailbreak (more limited)# re-sign the app with Frida gadget injected (objection patchipa), sideloadStatic analysis
Section titled “Static analysis”# the decrypted Mach-O binaryclass-dump / otool -l # classes, methods, Objective-C/Swift metadatastrings binary | grep -iE 'http|key|secret|password' # endpoints, secretsplutil -p Info.plist # URL schemes (deeplinks), ATS, permissions# look for NSAllowsArbitraryLoads (ATS disabled -> HTTP allowed)Dynamic analysis
Section titled “Dynamic analysis”# instrumentation with Frida (see mob-frida)frida -U -f com.target.app -l script.jsobjection -g com.target.app explore # explore, bypass, dump# bypass jailbreak detection and SSL pinning (mob-ssl)objection --gadget com.target.app explore -s "ios sslpinning disable"Typical attack vectors
Section titled “Typical attack vectors”# insecure storage (see mob-storage)# Keychain: objection ios keychain dump# app files in /var/mobile/Containers/Data/Application/<UUID>/# NSUserDefaults (.plist), SQLite databases, cache# URL schemes / Universal Links (deeplinks -> mob-deeplinks)# bypassable jailbreak detection (not real security)# pasteboard, background screenshots, logs# backend/API (the real target -> Web section)Keychain and sensitive data
Section titled “Keychain and sensitive data”The iOS Keychain is the “correct” place for secrets, but with a jailbreak it can be dumped:
objection -g com.target.app exploreios keychain dump # contents of the app's Keychain# review data-protection classes (kSecAttrAccessible...) -> accessible without unlock?For the defense
Section titled “For the defense”- Secrets in the Keychain with the right protection class (not in plist/NSUserDefaults/code).
- ATS enabled (no
NSAllowsArbitraryLoads); TLS + pinning (SSL Pinning and Bypass). - Data Protection (encryption tied to unlock) for sensitive files; clear cache/pasteboard.
- Jailbreak detection / anti-debug / obfuscation (RESILIENCE) raise the cost, don’t replace security.
- Validate URL schemes and Universal Links; all critical security in the backend.
Testing checklist
Section titled “Testing checklist”- Obtain and decrypt the IPA (frida-ios-dump)
- Environment: jailbreak or Frida gadget (no jailbreak)
- Static: class-dump, strings, Info.plist (URL schemes, ATS)
- Dynamic: Frida/Objection, bypass jailbreak detection
- Keychain dump and storage (Insecure Storage)
- SSL pinning bypass (SSL Pinning and Bypass)
- Deeplinks / Universal Links (Deeplinks and IPC)
- Backend/API (Web section)