daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

extracting-entitlements-from-compiled-application.md (4013B)


      1 ---
      2 title: "Extracting Entitlements from Compiled Application"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Extracting Entitlements from Compiled Application
     14 
     15 The procedures below preserve the original binary-carving approach from OWASP MASTG. Start with `codesign`, which asks the code-signing blob for its entitlements directly, then use carving when the signature is unavailable or malformed.<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 ```bash
     18 codesign -d --entitlements :- "Payload/Target.app" 2>/dev/null
     19 security cms -D -i "Payload/Target.app/embedded.mobileprovision"
     20 ```
     21 
     22 ### **Extracting Entitlements and Mobile Provision Files**
     23 
     24 An IPA or installed app may not contain a standalone `.entitlements` file. Effective signed entitlements are embedded in the Mach-O code signature, while `embedded.mobileprovision`—when present—contains the provisioning profile and its permitted entitlement set. These are related but not guaranteed to be identical.
     25 
     26 Even with encrypted binaries, certain steps can be employed to extract these files. Should these steps fail, tools such as Clutch (if compatible with the iOS version), frida-ios-dump, or similar utilities may be required to decrypt and extract the app.
     27 
     28 #### **Extracting the Entitlements Plist from the App Binary**
     29 
     30 With the app binary accessible on a computer, **binwalk** can be utilized to extract all XML files. The command below demonstrates how to do so:
     31 
     32 ```bash
     33 $ binwalk -e -y=xml ./Telegram\ X
     34 
     35 DECIMAL       HEXADECIMAL     DESCRIPTION
     36 --------------------------------------------------------------------------------
     37 1430180       0x15D2A4        XML document, version: "1.0"
     38 1458814       0x16427E        XML document, version: "1.0"
     39 ```
     40 
     41 Alternatively, **radare2** can be used to quietly run a command and exit, searching for all strings in the app binary that contain "PropertyList":
     42 
     43 ```bash
     44 $ r2 -qc 'izz~PropertyList' ./Telegram\ X
     45 
     46 0x0015d2a4 ascii <?xml version="1.0" encoding="UTF-8" standalone="yes"?>...
     47 0x0016427d ascii H<?xml version="1.0" encoding="UTF-8"?>...
     48 ```
     49 
     50 Both Binwalk and radare2 can locate embedded property-list text. In this Telegram example, the first XML object at `0x0015d2a4` corresponds to the project's entitlement file.<sup>[[3]](#references)</sup>
     51 
     52 For app binaries accessed on jailbroken devices (e.g., via SSH), the **grep** command with the `-a, --text` flag can be used to treat all files as ASCII text:
     53 
     54 ```bash
     55 $ grep -a -A 5 'PropertyList' /var/containers/Bundle/Application/...
     56 ```
     57 
     58 Adjusting the `-A num, --after-context=num` flag allows for the display of more or fewer lines. This method is viable even for encrypted app binaries and has been verified against multiple App Store apps. Tools mentioned earlier may also be employed on jailbroken iOS devices for similar purposes.
     59 
     60 > [!NOTE]
     61 > Plain `strings` may miss or truncate relevant data. Prefer code-signing tools, or use `grep -a`, radare2 (`izz`), and rabin2 (`-zz`) when carving is necessary.
     62 
     63 ## References
     64 
     65 - [1] [MASTG-TEST-0069: Review entitlements embedded in the compiled app binary - OWASP MASTG](https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0069/#review-entitlements-embedded-in-the-compiled-app-binary)
     66 - [2] [Apple — Code Signing Guide: Code Signing Tasks](https://developer.apple.com/library/archive/documentation/Security/Conceptual/CodeSigningGuide/Procedures/Procedures.html)
     67 - [3] [Telegram-iOS entitlement file used in the example](https://github.com/peter-iakovlev/Telegram-iOS/blob/77ee5c4dabdd6eb5f1e2ff76219edf7e18b45c00/Telegram-iOS/Telegram-iOS-AppStoreLLC.entitlements)