daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ios-pentesting-checklist.md (11456B)


      1 ---
      2 title: "iOS Pentesting Checklist"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting-checklist.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting-checklist.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # iOS Pentesting Checklist
     14 
     15 ### Preparation
     16 
     17 - [ ] Read [**iOS Basics**](/hacktricks/mobile-pentesting/ios-pentesting/ios-basics)
     18 - [ ] Read [**iOS Basic Testing Operations**](/hacktricks/mobile-pentesting/ios-pentesting/basic-ios-testing-operations) to learn current extraction, installation, and filesystem access workflows
     19 - [ ] Prepare your environment reading [**iOS Testing Environment**](/hacktricks/mobile-pentesting/ios-pentesting/ios-testing-environment)
     20 - [ ] If you are testing on **iOS 16+**, enable **Developer Mode** and decide if you need a simulator, a paired physical device (`xcrun devicectl`), or a jailbroken/rootless device
     21 - [ ] If a jailbreak isn't available, review [**iOS Pentesting without Jailbreak**](/hacktricks/mobile-pentesting/ios-pentesting/ios-pentesting-without-jailbreak)
     22 - [ ] Read all the sections of [**iOS Initial Analysis**](ios-pentesting/index.html#initial-analysis) to learn common actions to pentest an iOS application
     23 - [ ] Extract [**entitlements**](/hacktricks/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application) early and review **Associated Domains**, **App Groups**, **keychain access groups**, extension points, `get-task-allow`, and unusual capabilities
     24 - [ ] Review `Info.plist` for `CFBundleURLTypes`, `LSApplicationQueriesSchemes`, `NSAppTransportSecurity`, `WKAppBoundDomains`, and `.appex` extension declarations
     25 
     26 ### Data Storage
     27 
     28 - [ ] [**Plist files**](ios-pentesting/index.html#plist) can be used to store sensitive information.
     29 - [ ] [**Core Data**](ios-pentesting/index.html#core-data) (SQLite database) can store sensitive information.
     30 - [ ] [**YapDatabases**](ios-pentesting/index.html#yapdatabase) (SQLite database) can store sensitive information.
     31 - [ ] [**Firebase**](ios-pentesting/index.html#firebase-real-time-databases) misconfiguration.
     32 - [ ] [**Realm databases**](ios-pentesting/index.html#realm-databases) can store sensitive information.
     33 - [ ] [**Couchbase Lite databases**](ios-pentesting/index.html#couchbase-lite-databases) can store sensitive information.
     34 - [ ] [**Binary cookies**](ios-pentesting/index.html#cookies) can store sensitive information
     35 - [ ] [**Cache data**](ios-pentesting/index.html#cache) can store sensitive information
     36 - [ ] [**Automatic snapshots**](ios-pentesting/index.html#snapshots) can save visual sensitive information
     37 - [ ] [**Keychain**](ios-pentesting/index.html#keychain) is usually used to store sensitive information that can be left when reselling the phone.
     38 - [ ] If the app uses **App Groups**, inspect the **shared container** and **shared preferences** reachable by the main app, widgets, and share extensions<sup>[[1]](#references)</sup>
     39 - [ ] Review **Data Protection / NSFileProtection** classes in both the app container and any group container, especially files left as `NSFileProtectionNone` or `NSFileProtectionCompleteUntilFirstUserAuthentication`
     40 - [ ] Review **Keychain** item protections (`kSecAttrAccessible*`, `SecAccessControl`) and any **keychain access groups**; secrets intended to be device/biometry-bound should use restrictive flags such as `ThisDeviceOnly` / `biometryCurrentSet`
     41 - [ ] In summary, just **check for sensitive information saved by the application in the filesystem**
     42 
     43 ### Keyboards
     44 
     45 - [ ] Does the application [**allow the use of custom keyboards**](ios-pentesting/index.html#custom-keyboards-keyboard-cache)?
     46 - [ ] Check if sensitive information is saved in the [**keyboards cache files**](ios-pentesting/index.html#custom-keyboards-keyboard-cache)
     47 
     48 ### **Logs**
     49 
     50 - [ ] Check if [**sensitive information is being logged**](ios-pentesting/index.html#logs)
     51 - [ ] Check **unified logging** and crash artifacts in addition to app-controlled logs, especially after login, token refresh, deep link handling, and WebView activity
     52 
     53 ### Backups
     54 
     55 - [ ] [**Backups**](ios-pentesting/index.html#backups) can be used to **access sensitive information** saved in the file system (check the initial point of this checklist)
     56 - [ ] Also, [**backups**](ios-pentesting/index.html#backups) can be used to **modify some configurations of the application**, then **restore** the backup on the phone, and then as the **modified configuration** is **loaded** some (security) **functionality** may be **bypassed**
     57 - [ ] Verify whether secrets expected to be **device-only** or **non-migratable** survive backup / restore or device-to-device migration because the app uses a migratable Keychain class
     58 
     59 ### **Applications Memory**
     60 
     61 - [ ] Check for sensitive information inside the [**application's memory**](ios-pentesting/index.html#testing-memory-for-sensitive-data)
     62 
     63 ### **Broken Cryptography**
     64 
     65 - [ ] Check if you can find [**passwords used for cryptography**](ios-pentesting/index.html#broken-cryptography)
     66 - [ ] Check for the use of [**deprecated/weak algorithms**](ios-pentesting/index.html#broken-cryptography) to send/store sensitive data
     67 - [ ] [**Hook and monitor cryptography functions**](ios-pentesting/index.html#broken-cryptography)
     68 
     69 ### **Local Authentication**
     70 
     71 - [ ] If a [**local authentication**](ios-pentesting/index.html#local-authentication) is used in the application, you should check how the authentication is working.
     72   - [ ] If the app treats a successful [**Local Authentication Framework**](ios-pentesting/index.html#local-authentication-framework) callback as the only authorization check, test whether hooking that callback bypasses the gate. Stronger designs bind access to a Keychain key protected by `SecAccessControl` rather than trusting a Boolean result alone.
     73   - [ ] If it's using a [**function that can be dynamically bypassed**](ios-pentesting/index.html#local-authentication-using-keychain) you could create a custom Frida script
     74   - [ ] Check for **`LAContext` reuse** / `touchIDAuthenticationAllowableReuseDuration` so sensitive actions succeed because the device was recently unlocked instead of triggering a fresh biometric prompt
     75   - [ ] If keychain items are unlocked with biometrics, verify whether biometric enrollment changes invalidate them (`biometryCurrentSet`) or if they remain accessible unexpectedly
     76 
     77 ### Sensitive Functionality Exposure Through IPC
     78 
     79 - [**Custom URI Handlers / Deeplinks / Custom Schemes**](ios-pentesting/index.html#custom-uri-handlers-deeplinks-custom-schemes)
     80   - [ ] Check if the application is **registering any protocol/scheme**
     81   - [ ] Check if the application is **registering to use** any protocol/scheme
     82   - [ ] Check if the application **expects to receive any kind of sensitive information** from the custom scheme that can be **intercepted** by another application registering the same scheme
     83   - [ ] Check if the application **isn't checking and sanitizing** user input via the custom scheme and some **vulnerability can be exploited**
     84   - [ ] Check if the application **exposes any sensitive action** that can be called from anywhere via the custom scheme
     85   - [ ] If OAuth / SSO callbacks use **custom schemes**, test **scheme hijacking** with a malicious app and prefer claimed `https` / Universal Links for auth callbacks
     86 - [**Universal Links**](ios-pentesting/index.html#universal-links)
     87   - [ ] Check if the application is **registering any universal protocol/scheme**
     88   - [ ] Check the `apple-app-site-association` file
     89   - [ ] Audit the AASA for **wildcards / over-broad `paths` or `components`** and sensitive or unpublished routes
     90   - [ ] Verify undefined routes that still match AASA rules return **404** and that wildcard subdomains are not over-trusted
     91   - [ ] Check if the application **isn't checking and sanitizing** user input via the universal link and some **vulnerability can be exploited**
     92   - [ ] Check if the application **exposes any sensitive action** that can be called from anywhere via the universal link
     93 - [**UIActivity Sharing**](/hacktricks/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing)
     94   - [ ] Check if the application can receive UIActivities and if it's possible to exploit any vulnerability with specially crafted activity
     95 - [**UIPasteboard**](/hacktricks/mobile-pentesting/ios-pentesting/ios-uipasteboard)
     96   - [ ] Check if the application is **copying anything to the general pasteboard**
     97   - [ ] Check if the application is **using the data from the general pasteboard for anything**
     98   - [ ] Monitor the pasteboard to see if any **sensitive data is copied**
     99 - [**App Extensions**](/hacktricks/mobile-pentesting/ios-pentesting/ios-app-extensions)
    100   - [ ] Is the application **using any extension**?
    101   - [ ] Enumerate every `.appex`, inspect `NSExtensionActivationRule`, and map which **App Group** / shared container each extension can reach
    102 - [**WebViews**](/hacktricks/mobile-pentesting/ios-pentesting/ios-webviews)
    103   - [ ] Check which kind of webviews are being used
    104   - [ ] Check the status of **`javaScriptEnabled`**, **`JavaScriptCanOpenWindowsAutomatically`**, **`hasOnlySecureContent`**
    105   - [ ] Check if the webview can **access local files** with the protocol **`file://`** (`allowFileAccessFromFileURLs`, `allowUniversalAccessFromFileURLs`)
    106   - [ ] Check if JavaScript can access **native methods** (`JSContext`, `postMessage`)
    107   - [ ] Check if the app opted into `WKAppBoundDomains` / `limitsNavigationsToAppBoundDomains` when using hybrid content or privileged JS bridges<sup>[[2]](#references)</sup>
    108   - [ ] If `WKScriptMessageHandler` / `postMessage` bridges exist, confirm they validate the **current URL/origin/frame** before dispatching privileged native functionality
    109   - [ ] Check whether `WKWebView.isInspectable` / `JSContext.isInspectable` is enabled in production builds or can be flipped at runtime to inspect embedded JavaScript
    110 
    111 ### Network Communication
    112 
    113 - [ ] Perform a [**MitM to the communication**](ios-pentesting/index.html#network-communication) and search for web vulnerabilities.
    114 - [ ] Check if the [**hostname of the certificate**](ios-pentesting/index.html#hostname-check) is checked
    115 - [ ] Check/Bypass [**Certificate Pinning**](ios-pentesting/index.html#certificate-pinning)
    116 - [ ] Review `NSAppTransportSecurity` for `NSAllowsArbitraryLoads`, `NSAllowsArbitraryLoadsInWebContent`, `NSAllowsLocalNetworking`, per-domain `NSExceptionDomains`, and legacy `NSTemporaryException*` keys
    117 - [ ] If the app uses lower-level sockets, IP literals, or `.local` hosts, test those flows separately because ATS protections may not apply
    118 
    119 ### **Misc**
    120 
    121 - [ ] Check for [**automatic patching/updating**](ios-pentesting/index.html#hot-patching-enforced-updateing) mechanisms
    122 - [ ] Check for [**malicious third party libraries**](ios-pentesting/index.html#third-parties)
    123 - [ ] Review third-party SDKs / hybrid frameworks for embedded **WebViews**, **App Groups**, **custom URL schemes**, analytics beacons, or hot-patching logic that silently widens the attack surface
    124 
    125 ## References
    126 
    127 - [1] [Apple Platform Security: App protection and app groups in iOS, iPadOS, and visionOS](https://support.apple.com/en-us/guide/security/sec1a976c067/web)
    128 - [2] [WebKit: App-Bound Domains](https://webkit.org/blog/10882/app-bound-domains/)