daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

basic-ios-testing-operations.md (16257B)


      1 ---
      2 title: "iOS Basic Testing Operations"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting/basic-ios-testing-operations.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/basic-ios-testing-operations.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # iOS Basic Testing Operations
     14 
     15 ## **Summary of iOS Device Identification and Access**
     16 
     17 ### **Identifying the UDID of an iOS Device**
     18 
     19 To identify an iOS device uniquely, a 40-digit sequence known as the UDID is used. On macOS Catalina or newer, this can be found in the **Finder app**, as iTunes is no longer present. The device, once connected via USB and selected in Finder, reveals its UDID among other information when the details under its name are clicked through.<sup>[[1]](#references)</sup>
     20 
     21 For versions of macOS prior to Catalina, iTunes facilitates the discovery of the UDID. Detailed instructions can be found [here](http://www.iclarified.com/52179/how-to-find-your-iphones-udid).<sup>[[7]](#references)</sup>
     22 
     23 Command-line tools offer alternative methods for retrieving the UDID:<sup>[[1]](#references)</sup>
     24 
     25 - **Using I/O Registry Explorer tool `ioreg`:**
     26 
     27 ```bash
     28 $ ioreg -p IOUSB -l | grep "USB Serial"
     29 ```
     30 
     31 - **Using `ideviceinstaller` for macOS (and Linux):**
     32 
     33 ```bash
     34 $ brew install ideviceinstaller
     35 $ idevice_id -l
     36 ```
     37 
     38 - **Utilizing `system_profiler`:**
     39 
     40 ```bash
     41 $ system_profiler SPUSBDataType | sed -n -e '/iPad/,/Serial/p;/iPhone/,/Serial/p;/iPod/,/Serial/p' | grep "Serial Number:"
     42 ```
     43 
     44 - **Employing `instruments` to list devices:**
     45 
     46 ```bash
     47 $ instruments -s devices
     48 ```
     49 
     50 ### **Accessing the Device Shell**
     51 
     52 **SSH access** is enabled by installing the **OpenSSH package** post-jailbreak, allowing connections via `ssh root@<device_ip_address>`. It's crucial to change the default passwords (`alpine`) for users `root` and `mobile` to secure the device.<sup>[[2]](#references)</sup>
     53 
     54 **SSH over USB** becomes necessary in the absence of Wi-Fi, using `iproxy` to map device ports for SSH connections. This setup enables SSH access through USB by running:<sup>[[2]](#references)</sup>
     55 
     56 ```bash
     57 $ iproxy 2222 22
     58 $ ssh -p 2222 root@localhost
     59 ```
     60 
     61 **On-device shell applications**, like NewTerm 2, facilitate direct device interaction, especially useful for troubleshooting. **Reverse SSH shells** can also be established for remote access from the host computer.<sup>[[2]](#references)</sup>
     62 
     63 ### **Resetting Forgotten Passwords**
     64 
     65 To reset a forgotten password back to the default (`alpine`), editing the `/private/etc/master.passwd` file is necessary. This involves replacing the existing hash with the hash for `alpine` next to the `root` and `mobile` user entries.<sup>[[2]](#references)</sup>
     66 
     67 ## **Data Transfer Techniques**
     68 
     69 ### **Transferring App Data Files**
     70 
     71 **Archiving and Retrieval via SSH and SCP:** It's straightforward to archive the application's Data directory using `tar` and then transfer it using `scp`. The command below archives the Data directory into a .tgz file, which is then pulled from the device:<sup>[[3]](#references)</sup>
     72 
     73 ```bash
     74 tar czvf /tmp/data.tgz /private/var/mobile/Containers/Data/Application/8C8E7EB0-BC9B-435B-8EF8-8F5560EB0693
     75 exit
     76 scp -P 2222 root@localhost:/tmp/data.tgz .
     77 ```
     78 
     79 ### **Graphical User Interface Tools**
     80 
     81 **Using iFunbox and iExplorer:** These GUI tools are useful for managing files on iOS devices. However, starting with iOS 8.4, Apple restricted these tools' access to the application sandbox unless the device is jailbroken.<sup>[[3]](#references)</sup>
     82 
     83 ### **Using Objection for File Management**
     84 
     85 **Interactive Shell with Objection:** Launching objection provides access to the Bundle directory of an app. From here, you can navigate to the app's Documents directory and manage files, including downloading and uploading them to and from the iOS device.<sup>[[3]](#references)</sup>
     86 
     87 ```bash
     88 objection --gadget com.apple.mobilesafari explorer
     89 cd /var/mobile/Containers/Data/Application/72C7AAFB-1D75-4FBA-9D83-D8B4A2D44133/Documents
     90 file download <filename>
     91 ```
     92 
     93 ## **Obtaining and Extracting Apps**
     94 
     95 ### **Acquiring the IPA File**
     96 
     97 **Over-The-Air (OTA) Distribution Link:** Apps distributed for testing via OTA can be downloaded using the ITMS services asset downloader tool, which is installed via npm and used to save the IPA file locally.
     98 
     99 ```bash
    100 npm install -g itms-services
    101 itms-services -u "itms-services://?action=download-manifest&url=https://s3-ap-southeast-1.amazonaws.com/test-uat/manifest.plist" -o - > out.ipa
    102 ```
    103 
    104 ### **Extracting the App Binary**
    105 
    106 1. **From an IPA:** Unzip the IPA to access the decrypted app binary.
    107 2. **From a Jailbroken Device:** Install the app and extract the decrypted binary from memory.<sup>[[4]](#references)</sup>
    108 
    109 ### **Decryption Process**
    110 
    111 **Manual Decryption Overview:** iOS app binaries are encrypted by Apple using FairPlay. To reverse-engineer, one must dump the decrypted binary from memory. The decryption process involves checking for the PIE flag, adjusting memory flags, identifying the encrypted section, and then dumping and replacing this section with its decrypted form.<sup>[[4]](#references)</sup>
    112 
    113 **Checking and Modifying PIE Flag:**
    114 
    115 ```bash
    116 otool -Vh Original_App
    117 python change_macho_flags.py --no-pie Original_App
    118 otool -Vh Hello_World
    119 ```
    120 
    121 **Identifying Encrypted Section and Dumping Memory:**
    122 
    123 Determine the encrypted section's start and end addresses using `otool` and dump the memory from the jailbroken device using gdb.
    124 
    125 ```bash
    126 otool -l Original_App | grep -A 4 LC_ENCRYPTION_INFO
    127 dump memory dump.bin 0x8000 0x10a4000
    128 ```
    129 
    130 **Overwriting the Encrypted Section:**
    131 
    132 Replace the encrypted section in the original app binary with the decrypted dump.
    133 
    134 ```bash
    135 dd bs=1 seek=<starting_address> conv=notrunc if=dump.bin of=Original_App
    136 ```
    137 
    138 **Finalizing Decryption:** Modify the binary's metadata to indicate the absence of encryption using tools like **MachOView**, setting the `cryptid` to 0.
    139 
    140 ### **FairPlay-aware partial analysis**
    141 
    142 FairPlay does not make the complete `.app` bundle opaque: it protects a byte range of each encrypted Mach-O, described by `LC_ENCRYPTION_INFO` or `LC_ENCRYPTION_INFO_64` (`cryptoff`, `cryptsize`, and `cryptid`). Therefore, failure to obtain a decrypted main executable should switch the assessment to a **partial** mode instead of stopping it.<sup>[[8]](#references)[[9]](#references)</sup>
    143 
    144 Check every executable Mach-O independently because the main executable and embedded frameworks can have different encryption states. `cryptid 1` identifies an encrypted range; a successfully dumped output should be re-parsed and report `cryptid 0`.<sup>[[8]](#references)</sup>
    145 
    146 ```bash
    147 APP=Payload/Example.app
    148 find "$APP" -type f -perm -111 -exec sh -c '
    149   file "$1" | grep -q "Mach-O" || exit 0
    150   echo "### $1"
    151   otool -l "$1" | grep -A 4 -E "LC_ENCRYPTION_INFO(_64)?"
    152 ' sh {} \;
    153 ```
    154 
    155 #### Apple Silicon acquisition attempt
    156 
    157 On Apple Silicon, first try acquiring the **official Mac-targeted copy** of a compatible iPhone/iPad app. This path is available only when the developer permits Mac distribution in App Store Connect under **Pricing and Availability → iPhone and iPad Apps on Apple Silicon Mac**; it is an optimization, not a universal replacement for device dumping.<sup>[[8]](#references)[[9]](#references)[[10]](#references)</sup>
    158 
    159 [MobHunt](https://github.com/ivRodriguezCA/MobHunt) automates this workflow. Its acquisition helper uses `ipatool --device-family mac` to request a Mac-platform package, then attempts `mremap_encrypted`-based decryption and verifies the resulting Mach-O files.<sup>[[8]](#references)</sup>
    160 
    161 ```bash
    162 brew install ipatool
    163 ipatool auth login -e <apple-id-email> # Password and 2FA are prompted interactively
    164 ipatool download -b <bundle-id> -o ./ipas --device-family mac
    165 
    166 # From a MobHunt checkout:
    167 ./tools/decryption/decrypt_ipa.sh --ipa ./ipas/<app>.ipa --output ./decrypted
    168 ```
    169 
    170 Do not infer success merely because an IPA was downloaded or a tool produced output. Record `analysis_mode: full` only after checking the required Mach-O outputs; otherwise record `analysis_mode: partial` and constrain subsequent tools to plaintext inputs.<sup>[[8]](#references)[[9]](#references)</sup>
    171 
    172 #### Productive partial-mode triage
    173 
    174 The following bundle artifacts remain useful without native-code decryption and should be analyzed before seeking a jailbreak-based dump.<sup>[[8]](#references)[[9]](#references)</sup>
    175 
    176 | Artifact | High-signal review |
    177 | --- | --- |
    178 | `Info.plist` | URL schemes, associated domains, ATS exceptions, app groups, permission strings and routing configuration |
    179 | Entitlements and `embedded.mobileprovision` | Keychain groups, application groups, capabilities, Team ID and provisioning constraints |
    180 | `.plist`, `.json`, `.strings`, `Settings.bundle` and Core Data models | Endpoints, cloud configuration, feature/debug flags, credentials and local schemas |
    181 | `Frameworks/` and `.dylib` files | SDK inventory; test each Mach-O separately because some embedded code may be unencrypted |
    182 | React Native JavaScript or Hermes bundles | Business logic, endpoints and secrets that remain outside the protected native-code range |
    183 
    184 ```bash
    185 plutil -p "$APP/Info.plist"
    186 codesign -d --entitlements :- "$APP" 2>/dev/null
    187 security cms -D -i "$APP/embedded.mobileprovision" 2>/dev/null | plutil -p -
    188 find "$APP" -type f \( -name '*.plist' -o -name '*.json' -o -name '*.strings' \
    189   -o -name '*.jsbundle' -o -name '*.bundle' \) -print
    190 ```
    191 
    192 In partial mode, do **not** trust disassembly/decompilation of encrypted code, Swift metadata recovered from protected sections, or `strings` output attributed to encrypted `__TEXT`; these operations can produce noise that looks like valid evidence. Run them only against binaries or ranges whose decrypted state was verified.<sup>[[8]](#references)[[9]](#references)</sup>
    193 
    194 ### **Decryption (Automatically)**
    195 
    196 #### **frida-ios-dump**
    197 
    198 The [**frida-ios-dump**](https://github.com/AloneMonkey/frida-ios-dump) tool is employed for **automatically decrypting and extracting apps** from iOS devices. Initially, one must configure `dump.py` to connect to the iOS device, which can be done through localhost on port 2222 via **iproxy** or directly via the device's IP address and port.<sup>[[4]](#references)</sup>
    199 
    200 Applications installed on the device can be listed with the command:
    201 
    202 ```bash
    203 $ python dump.py -l
    204 ```
    205 
    206 To dump a specific app, such as Telegram, the following command is used:
    207 
    208 ```bash
    209 $ python3 dump.py -u "root" -p "<PASSWORD>" ph.telegra.Telegraph
    210 ```
    211 
    212 This command initiates the app dump, resulting in the creation of a `Telegram.ipa` file in the current directory. This process is suitable for jailbroken devices, as unsigned or fake-signed apps can be reinstalled using tools like [**ios-deploy**](https://github.com/ios-control/ios-deploy).
    213 
    214 #### **frida-ipa-extract**
    215 
    216 Frida-based IPA extractor for jailbroken devices; uses USB Frida sessions and optional SSH/SFTP for faster pulls.<sup>[[6]](#references)</sup>
    217 
    218 - Requirements: Python **3.9+**, `frida`, `paramiko`, jailbroken device with **frida-server** (OpenSSH for SSH mode).
    219 - Setup:
    220 
    221 ```bash
    222 python3 -m venv .venv
    223 source .venv/bin/activate
    224 pip install -r requirements.txt
    225 ```
    226 
    227 - Usage:
    228 
    229 ```bash
    230 python extract.py -U -f com.example.app -o MyApp.ipa
    231 python extract.py -U -f com.example.app -o MyApp.ipa --sandbox --no-resume
    232 python extract.py -H 192.168.100.32 -P 2222 -u root -p password -f com.example.app
    233 ```
    234 
    235 - Flags: `-f <bundle>` spawns/attaches (or `--pid` for PID); `-o` sets output name. `-U` uses USB; `-H/-P/-u/-p` opens an SSH tunnel to `frida-server` 27042 and pulls via SFTP (can combine with `-U`). `--sandbox` dumps the sandbox; `--no-resume` keeps the app suspended to avoid crashes and retries via a system process if the session drops.
    236 - Troubleshooting: `Frida attach timed out` → use `-f` or `--no-resume`; `script has been destroyed` → `--no-resume` or SSH transfer; `No running apps found` → start or spawn the app.
    237 
    238 #### **flexdecrypt**
    239 
    240 The [**flexdecrypt**](https://github.com/JohnCoates/flexdecrypt) tool, along with its wrapper [**flexdump**](https://gist.github.com/defparam/71d67ee738341559c35c684d659d40ac), allows for the extraction of IPA files from installed applications. Installation commands for **flexdecrypt** on the device include downloading and installing the `.deb` package. **flexdump** can be used to list and dump apps, as shown in the commands below:
    241 
    242 ```bash
    243 apt install zip unzip
    244 wget https://gist.githubusercontent.com/defparam/71d67ee738341559c35c684d659d40ac/raw/30c7612262f1faf7871ba8e32fbe29c0f3ef9e27/flexdump -P /usr/local/bin; chmod +x /usr/local/bin/flexdump
    245 flexdump list
    246 flexdump dump Twitter.app
    247 ```
    248 
    249 #### **bagbak**
    250 
    251 [**bagbak**](https://github.com/ChiChou/bagbak), another Frida-based tool, requires a jailbroken device for app decryption:
    252 
    253 ```bash
    254 bagbak --raw Chrome
    255 ```
    256 
    257 #### **r2flutch**
    258 
    259 **r2flutch**, utilizing both radare and frida, serves for app decryption and dumping. More information can be found on its [**GitHub page**](https://github.com/as0ler/r2flutch).
    260 
    261 ### **Installing Apps**
    262 
    263 **Sideloading** refers to installing applications outside the official App Store. This process is handled by the **installd daemon** and requires apps to be signed with an Apple-issued certificate. Jailbroken devices can bypass this through **AppSync**, enabling the installation of fake-signed IPA packages.<sup>[[5]](#references)</sup>
    264 
    265 #### **Sideloading Tools**
    266 
    267 - **Cydia Impactor**: A tool for signing and installing IPA files on iOS and APK files on Android. Guides and troubleshooting can be found on [yalujailbreak.net](https://yalujailbreak.net/how-to-use-cydia-impactor/).
    268 
    269 - **libimobiledevice**: A library for Linux and macOS to communicate with iOS devices. Installation commands and usage examples for ideviceinstaller are provided for installing apps over USB.
    270 
    271 - **ipainstaller**: This command-line tool allows direct app installation on iOS devices.
    272 
    273 - **ios-deploy**: For macOS users, ios-deploy installs iOS apps from the command line. Unzipping the IPA and using the `-m` flag for direct app launch are part of the process.
    274 
    275 - **Xcode**: Utilize Xcode to install apps by navigating to **Window/Devices and Simulators** and adding the app to **Installed Apps**.
    276 
    277 #### **Allow Application Installation on Non-iPad Devices**
    278 
    279 To install iPad-specific applications on iPhone or iPod touch devices, the **UIDeviceFamily** value in the **Info.plist** file needs to be changed to **1**. This modification, however, requires re-signing the IPA file due to signature validation checks.
    280 
    281 **Note**: This method might fail if the application demands capabilities exclusive to newer iPad models while using an older iPhone or iPod touch.<sup>[[5]](#references)</sup>
    282 
    283 ## References
    284 
    285 - [1] [iOS Security Testing - OWASP MASTG](https://mas.owasp.org/MASTG/0x06b-iOS-Security-Testing/)
    286 - [2] [MASTG-TECH-0052: Accessing the Device Shell - OWASP MASTG](https://mas.owasp.org/MASTG/techniques/ios/MASTG-TECH-0052/)
    287 - [3] [MASTG-TECH-0053: Host-Device Data Transfer - OWASP MASTG](https://mas.owasp.org/MASTG/techniques/ios/MASTG-TECH-0053/)
    288 - [4] [MASTG-TECH-0054: Obtaining and Extracting Apps - OWASP MASTG](https://mas.owasp.org/MASTG/techniques/ios/MASTG-TECH-0054/)
    289 - [5] [MASTG-TECH-0056: Installing Apps - OWASP MASTG](https://mas.owasp.org/MASTG/techniques/ios/MASTG-TECH-0056/)
    290 - [6] [frida-ipa-extract](https://github.com/lautarovculic/frida-ipa-extract)
    291 - [7] [iclarified.com - How To Find Your Iphones Udid](http://www.iclarified.com/52179/how-to-find-your-iphones-udid)
    292 - [8] [MobHunt - iOS FairPlay decryption and partial-analysis workflow](https://github.com/ivRodriguezCA/MobHunt/blob/main/docs/ios-decryption.md)
    293 - [9] [Introducing MobHunt: Agentic Mobile Bug Bounty Hunting](https://ivrodriguez.com/introducing-mobhunt)
    294 - [10] [Apple - Manage availability of iPhone and iPad apps on Macs with Apple silicon](https://developer.apple.com/help/app-store-connect/manage-your-apps-availability/manage-availability-of-iphone-and-ipad-apps-on-macs-with-apple-silicon/)