daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ios-uiactivity-sharing.md (3634B)


      1 ---
      2 title: "iOS UIActivity Sharing"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # iOS UIActivity Sharing
     14 
     15 ## UIActivity Sharing Simplified
     16 
     17 Since iOS 6, applications can present a system activity view to share text, URLs, images, and other items with services such as AirDrop or compatible app extensions.<sup>[[2]](#references)</sup>
     18 
     19 Apple's `UIActivity.ActivityType` documentation enumerates built-in activity identifiers. Developers can set `excludedActivityTypes`, but the security review must also inspect the actual items and any custom activities.<sup>[[3]](#references)</sup>
     20 
     21 ## **How to Share Data**
     22 
     23 Attention should be directed towards:<sup>[[1]](#references)</sup>
     24 
     25 - The nature of the data being shared.
     26 - The inclusion of custom activities.
     27 - The exclusion of certain activity types.
     28 
     29 Sharing is facilitated through the instantiation of a `UIActivityViewController`, to which the items intended for sharing are passed. This is achieved by calling:
     30 
     31 ```bash
     32 $ rabin2 -zq Telegram\ X.app/Telegram\ X | grep -i activityItems
     33 0x1000df034 45 44 initWithActivityItems:applicationActivities:
     34 ```
     35 
     36 Review the items and custom activities passed to `UIActivityViewController`, along with any configured `excludedActivityTypes`.
     37 
     38 ## **How to Receive Data**
     39 
     40 The following aspects are crucial when receiving data:<sup>[[1]](#references)</sup>
     41 
     42 - The declaration of **custom document types**.
     43 - The specification of **document types the app can open**.
     44 - The verification of the **integrity of the received data**.
     45 
     46 Without source, inspect `Info.plist` for `UTExportedTypeDeclarations`, `UTImportedTypeDeclarations`, and `CFBundleDocumentTypes`. These legacy UTI keys still appear in deployed apps; newer source commonly uses the Uniform Type Identifiers framework and `UTType` APIs.<sup>[[4]](#references)</sup>
     47 
     48 Exported declarations define types owned by the app, imported declarations describe types owned elsewhere, and document types associate those identifiers with the app's open/import behavior.<sup>[[4]](#references)</sup>
     49 
     50 ## Dynamic Testing Approach
     51 
     52 To test **sending activities**, one could:<sup>[[1]](#references)</sup>
     53 
     54 - Hook into the `init(activityItems:applicationActivities:)` method to capture the items and activities being shared.
     55 - Identify excluded activities by intercepting the `excludedActivityTypes` property.
     56 
     57 For **receiving items**, it involves:<sup>[[1]](#references)</sup>
     58 
     59 - Sharing a file with the app from another source (e.g., AirDrop, email) that prompts the "Open with..." dialogue.
     60 - Hooking `application:openURL:options:` among other methods identified during static analysis to observe the app's response.
     61 - Employing malformed files or fuzzing techniques to evaluate the app's robustness.
     62 
     63 ## References
     64 
     65 - [1] [OWASP MASTG — Testing App Extensions](https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0072/)
     66 - [2] [Apple — `UIActivityViewController`](https://developer.apple.com/documentation/uikit/uiactivityviewcontroller)
     67 - [3] [Apple — `UIActivity.ActivityType`](https://developer.apple.com/documentation/uikit/uiactivity/activitytype)
     68 - [4] [Apple — Defining file and data types for your app](https://developer.apple.com/documentation/uniformtypeidentifiers/defining-file-and-data-types-for-your-app)