ios-serialisation-and-encoding.md (4507B)
1 --- 2 title: "iOS Serialisation and Encoding" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/ios-pentesting/ios-serialisation-and-encoding.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/ios-serialisation-and-encoding.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # iOS Serialisation and Encoding 14 15 OWASP's object-serialization guidance provides additional code and testing context.<sup>[[1]](#references)</sup> 16 17 ## Object Serialization in iOS Development 18 19 In iOS, **object serialization** converts objects into a representation that can be stored or transmitted and reconstructed later. `NSCoding` and `NSSecureCoding` support keyed archives for Objective-C-compatible object graphs, commonly producing `Data`/`NSData`; Swift value types commonly use `Codable` instead.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 20 21 ### **`NSCoding`** Implementation 22 23 To implement `NSCoding`, a class must inherit from `NSObject` or be marked as `@objc`. This protocol mandates the implementation of two methods for encoding and decoding instance variables: 24 25 ```swift 26 class CustomPoint: NSObject, NSCoding { 27 var x: Double = 0.0 28 var name: String = "" 29 30 func encode(with aCoder: NSCoder) { 31 aCoder.encode(x, forKey: "x") 32 aCoder.encode(name, forKey: "name") 33 } 34 35 required convenience init?(coder aDecoder: NSCoder) { 36 guard let name = aDecoder.decodeObject(forKey: "name") as? String else { return nil } 37 self.init(x: aDecoder.decodeDouble(forKey: "x"), name: name) 38 } 39 } 40 ``` 41 42 ### **Enhancing Security with `NSSecureCoding`** 43 44 To reduce object-substitution attacks during unarchiving, **`NSSecureCoding`** requires callers to declare the expected classes and conforming classes to opt in. It improves type safety but does not encrypt or authenticate the archive, so untrusted or sensitive data may still require separate confidentiality and integrity controls.<sup>[[2]](#references)</sup> 45 46 ```swift 47 static var supportsSecureCoding: Bool { 48 return true 49 } 50 51 let obj = decoder.decodeObject(of: MyClass.self, forKey: "myKey") 52 ``` 53 54 ## Data Archiving with `NSKeyedArchiver` 55 56 `NSKeyedArchiver` and `NSKeyedUnarchiver` encode and decode object graphs. The following legacy APIs illustrate older code that may still appear during review, but Apple deprecated them; new code should use secure archiving/unarchiving APIs that specify the expected root class.<sup>[[3]](#references)</sup> 57 58 ```swift 59 NSKeyedArchiver.archiveRootObject(customPoint, toFile: "/path/to/archive") 60 let customPoint = NSKeyedUnarchiver.unarchiveObjectWithFile("/path/to/archive") as? CustomPoint 61 ``` 62 63 ### Using `Codable` for Simplified Serialization 64 65 Swift's `Codable` protocol combines `Decodable` and `Encodable`, facilitating the encoding and decoding of objects like `String`, `Int`, `Double`, etc., without extra effort: 66 67 ```swift 68 struct CustomPointStruct: Codable { 69 var x: Double 70 var name: String 71 } 72 ``` 73 74 This approach supports straightforward serialization to and from property lists and JSON.<sup>[[4]](#references)</sup> 75 76 ## JSON and XML Encoding Alternatives 77 78 Beyond native support, several third-party libraries offer JSON and XML encoding/decoding capabilities, each with its own performance characteristics and security considerations. It's imperative to carefully select these libraries, especially to mitigate vulnerabilities like XXE (XML External Entities) attacks by configuring parsers to prevent external entity processing. 79 80 ### Security Considerations 81 82 When serializing data, especially to the file system, it's essential to be vigilant about the potential inclusion of sensitive information. Serialized data, if intercepted or improperly handled, can expose applications to risks such as unauthorized actions or data leakage. Encrypting and signing serialized data is recommended to enhance security. 83 84 ## References 85 86 - [1] [OWASP MASTG - Object Serialization](https://mas.owasp.org/MASTG-KNOW-0075/) 87 - [2] [Apple - `NSSecureCoding`](https://developer.apple.com/documentation/foundation/nssecurecoding) 88 - [3] [Apple - `NSKeyedArchiver`](https://developer.apple.com/documentation/foundation/nskeyedarchiver) 89 - [4] [Apple - Encoding and Decoding Custom Types](https://developer.apple.com/documentation/foundation/archives_and_serialization/encoding_and_decoding_custom_types)