daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ios-serialisation-and-encoding.md (4507B)


      1 ---
      2 title: "iOS Serialisation and Encoding"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting/ios-serialisation-and-encoding.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/ios-serialisation-and-encoding.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # iOS Serialisation and Encoding
     14 
     15 OWASP's object-serialization guidance provides additional code and testing context.<sup>[[1]](#references)</sup>
     16 
     17 ## Object Serialization in iOS Development
     18 
     19 In iOS, **object serialization** converts objects into a representation that can be stored or transmitted and reconstructed later. `NSCoding` and `NSSecureCoding` support keyed archives for Objective-C-compatible object graphs, commonly producing `Data`/`NSData`; Swift value types commonly use `Codable` instead.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     20 
     21 ### **`NSCoding`** Implementation
     22 
     23 To implement `NSCoding`, a class must inherit from `NSObject` or be marked as `@objc`. This protocol mandates the implementation of two methods for encoding and decoding instance variables:
     24 
     25 ```swift
     26 class CustomPoint: NSObject, NSCoding {
     27     var x: Double = 0.0
     28     var name: String = ""
     29 
     30     func encode(with aCoder: NSCoder) {
     31         aCoder.encode(x, forKey: "x")
     32         aCoder.encode(name, forKey: "name")
     33     }
     34 
     35     required convenience init?(coder aDecoder: NSCoder) {
     36         guard let name = aDecoder.decodeObject(forKey: "name") as? String else { return nil }
     37         self.init(x: aDecoder.decodeDouble(forKey: "x"), name: name)
     38     }
     39 }
     40 ```
     41 
     42 ### **Enhancing Security with `NSSecureCoding`**
     43 
     44 To reduce object-substitution attacks during unarchiving, **`NSSecureCoding`** requires callers to declare the expected classes and conforming classes to opt in. It improves type safety but does not encrypt or authenticate the archive, so untrusted or sensitive data may still require separate confidentiality and integrity controls.<sup>[[2]](#references)</sup>
     45 
     46 ```swift
     47 static var supportsSecureCoding: Bool {
     48     return true
     49 }
     50 
     51 let obj = decoder.decodeObject(of: MyClass.self, forKey: "myKey")
     52 ```
     53 
     54 ## Data Archiving with `NSKeyedArchiver`
     55 
     56 `NSKeyedArchiver` and `NSKeyedUnarchiver` encode and decode object graphs. The following legacy APIs illustrate older code that may still appear during review, but Apple deprecated them; new code should use secure archiving/unarchiving APIs that specify the expected root class.<sup>[[3]](#references)</sup>
     57 
     58 ```swift
     59 NSKeyedArchiver.archiveRootObject(customPoint, toFile: "/path/to/archive")
     60 let customPoint = NSKeyedUnarchiver.unarchiveObjectWithFile("/path/to/archive") as? CustomPoint
     61 ```
     62 
     63 ### Using `Codable` for Simplified Serialization
     64 
     65 Swift's `Codable` protocol combines `Decodable` and `Encodable`, facilitating the encoding and decoding of objects like `String`, `Int`, `Double`, etc., without extra effort:
     66 
     67 ```swift
     68 struct CustomPointStruct: Codable {
     69     var x: Double
     70     var name: String
     71 }
     72 ```
     73 
     74 This approach supports straightforward serialization to and from property lists and JSON.<sup>[[4]](#references)</sup>
     75 
     76 ## JSON and XML Encoding Alternatives
     77 
     78 Beyond native support, several third-party libraries offer JSON and XML encoding/decoding capabilities, each with its own performance characteristics and security considerations. It's imperative to carefully select these libraries, especially to mitigate vulnerabilities like XXE (XML External Entities) attacks by configuring parsers to prevent external entity processing.
     79 
     80 ### Security Considerations
     81 
     82 When serializing data, especially to the file system, it's essential to be vigilant about the potential inclusion of sensitive information. Serialized data, if intercepted or improperly handled, can expose applications to risks such as unauthorized actions or data leakage. Encrypting and signing serialized data is recommended to enhance security.
     83 
     84 ## References
     85 
     86 - [1] [OWASP MASTG - Object Serialization](https://mas.owasp.org/MASTG-KNOW-0075/)
     87 - [2] [Apple - `NSSecureCoding`](https://developer.apple.com/documentation/foundation/nssecurecoding)
     88 - [3] [Apple - `NSKeyedArchiver`](https://developer.apple.com/documentation/foundation/nskeyedarchiver)
     89 - [4] [Apple - Encoding and Decoding Custom Types](https://developer.apple.com/documentation/foundation/archives_and_serialization/encoding_and_decoding_custom_types)