extracting-entitlements-from-compiled-application.md (4013B)
1 --- 2 title: "Extracting Entitlements from Compiled Application" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Extracting Entitlements from Compiled Application 14 15 The procedures below preserve the original binary-carving approach from OWASP MASTG. Start with `codesign`, which asks the code-signing blob for its entitlements directly, then use carving when the signature is unavailable or malformed.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 ```bash 18 codesign -d --entitlements :- "Payload/Target.app" 2>/dev/null 19 security cms -D -i "Payload/Target.app/embedded.mobileprovision" 20 ``` 21 22 ### **Extracting Entitlements and Mobile Provision Files** 23 24 An IPA or installed app may not contain a standalone `.entitlements` file. Effective signed entitlements are embedded in the Mach-O code signature, while `embedded.mobileprovision`—when present—contains the provisioning profile and its permitted entitlement set. These are related but not guaranteed to be identical. 25 26 Even with encrypted binaries, certain steps can be employed to extract these files. Should these steps fail, tools such as Clutch (if compatible with the iOS version), frida-ios-dump, or similar utilities may be required to decrypt and extract the app. 27 28 #### **Extracting the Entitlements Plist from the App Binary** 29 30 With the app binary accessible on a computer, **binwalk** can be utilized to extract all XML files. The command below demonstrates how to do so: 31 32 ```bash 33 $ binwalk -e -y=xml ./Telegram\ X 34 35 DECIMAL HEXADECIMAL DESCRIPTION 36 -------------------------------------------------------------------------------- 37 1430180 0x15D2A4 XML document, version: "1.0" 38 1458814 0x16427E XML document, version: "1.0" 39 ``` 40 41 Alternatively, **radare2** can be used to quietly run a command and exit, searching for all strings in the app binary that contain "PropertyList": 42 43 ```bash 44 $ r2 -qc 'izz~PropertyList' ./Telegram\ X 45 46 0x0015d2a4 ascii <?xml version="1.0" encoding="UTF-8" standalone="yes"?>... 47 0x0016427d ascii H<?xml version="1.0" encoding="UTF-8"?>... 48 ``` 49 50 Both Binwalk and radare2 can locate embedded property-list text. In this Telegram example, the first XML object at `0x0015d2a4` corresponds to the project's entitlement file.<sup>[[3]](#references)</sup> 51 52 For app binaries accessed on jailbroken devices (e.g., via SSH), the **grep** command with the `-a, --text` flag can be used to treat all files as ASCII text: 53 54 ```bash 55 $ grep -a -A 5 'PropertyList' /var/containers/Bundle/Application/... 56 ``` 57 58 Adjusting the `-A num, --after-context=num` flag allows for the display of more or fewer lines. This method is viable even for encrypted app binaries and has been verified against multiple App Store apps. Tools mentioned earlier may also be employed on jailbroken iOS devices for similar purposes. 59 60 > [!NOTE] 61 > Plain `strings` may miss or truncate relevant data. Prefer code-signing tools, or use `grep -a`, radare2 (`izz`), and rabin2 (`-zz`) when carving is necessary. 62 63 ## References 64 65 - [1] [MASTG-TEST-0069: Review entitlements embedded in the compiled app binary - OWASP MASTG](https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0069/#review-entitlements-embedded-in-the-compiled-app-binary) 66 - [2] [Apple — Code Signing Guide: Code Signing Tasks](https://developer.apple.com/library/archive/documentation/Security/Conceptual/CodeSigningGuide/Procedures/Procedures.html) 67 - [3] [Telegram-iOS entitlement file used in the example](https://github.com/peter-iakovlev/Telegram-iOS/blob/77ee5c4dabdd6eb5f1e2ff76219edf7e18b45c00/Telegram-iOS/Telegram-iOS-AppStoreLLC.entitlements)