{"id":13589477,"url":"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet","last_synced_at":"2025-07-27T06:34:31.044Z","repository":{"id":49518814,"uuid":"437304045","full_name":"ivan-sincek/ios-penetration-testing-cheat-sheet","owner":"ivan-sincek","description":"Work in progress...","archived":false,"fork":false,"pushed_at":"2024-07-15T19:57:23.000Z","size":3240,"stargazers_count":307,"open_issues_count":0,"forks_count":56,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-10-30T02:36:33.196Z","etag":null,"topics":["bug-bounty","ethical-hacking","frida","ios","ios-penetration-testing","mobile-penetration-testing","mobsf","objection","offensive-security","penetration-testing","red-team-engagement","security","unc0ver"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ivan-sincek.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-12-11T14:27:40.000Z","updated_at":"2024-10-29T19:18:43.000Z","dependencies_parsed_at":"2023-11-30T11:25:01.216Z","dependency_job_id":"de0389b1-279d-43ee-b35b-50e0c013bc96","html_url":"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fios-penetration-testing-cheat-sheet","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fios-penetration-testing-cheat-sheet/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fios-penetration-testing-cheat-sheet/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fios-penetration-testing-cheat-sheet/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ivan-sincek","download_url":"https://codeload.github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245644873,"owners_count":20649275,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bug-bounty","ethical-hacking","frida","ios","ios-penetration-testing","mobile-penetration-testing","mobsf","objection","offensive-security","penetration-testing","red-team-engagement","security","unc0ver"],"created_at":"2024-08-01T16:00:30.627Z","updated_at":"2025-07-27T06:34:31.011Z","avatar_url":"https://github.com/ivan-sincek.png","language":"JavaScript","funding_links":[],"categories":["Mobile Pentesting"],"sub_categories":["Apple"],"readme":"# iOS Penetration Testing Cheat Sheet\n\nThis is more of a checklist for myself. May contain useful tips and tricks. **Still need to add a lot of things.**\n\nEverything was tested on Kali Linux v2024.2 (64-bit) and iPhone 7 with iOS v13.4.1 and unc0ver jailbreak v8.0.2.\n\nFor help with any of the tools type `\u003ctool_name\u003e [-h | -hh | --help]` or `man \u003ctool_name\u003e`.\n\nIf you didn't already, read [OWAS MASTG](https://mas.owasp.org/MASTG/) \\([GitHub](https://github.com/OWASP/owasp-mastg)\\) and [OWASP MASVS](https://mas.owasp.org/MASVS/) \\([GitHub](https://github.com/OWASP/owasp-masvs)\\). You can download OWASP MASTG checklist from [here](https://github.com/OWASP/owasp-mastg/releases).\n\nI also recommend reading [Hacking iOS Applications](https://web.securityinnovation.com/hubfs/iOS%20Hacking%20Guide.pdf) and [HackTricks - iOS Pentesting](https://book.hacktricks.xyz/mobile-apps-pentesting/ios-pentesting).\n\n__In most cases, to be eligible for a bug bounty reward, you need to exploit a vulnerability with non-root priviledges, possibly building your own \"malicious\" app.__\n\nWebsites that you should use while writing the report:\n\n* [cwe.mitre.org/data](https://cwe.mitre.org/data)\n* [owasp.org/projects](https://owasp.org/projects)\n* [owasp.org/www-project-mobile-top-10](https://owasp.org/www-project-mobile-top-10)\n* [cheatsheetseries.owasp.org](https://cheatsheetseries.owasp.org/Glossary.html)\n* [first.org/cvss/calculator/4.0](https://www.first.org/cvss/calculator/4.0)\n* [bugcrowd.com/vulnerability-rating-taxonomy](https://bugcrowd.com/vulnerability-rating-taxonomy)\n* [nvd.nist.gov/ncp/repository](https://nvd.nist.gov/ncp/repository)\n* [attack.mitre.org](https://attack.mitre.org)\n\nMy other cheat sheets:\n\n* [Android Testing Cheat Sheet](https://github.com/ivan-sincek/android-penetration-testing-cheat-sheet)\n* [Penetration Testing Cheat Sheet](https://github.com/ivan-sincek/penetration-testing-cheat-sheet)\n* [WiFi Penetration Testing Cheat Sheet](https://github.com/ivan-sincek/wifi-penetration-testing-cheat-sheet)\n\nFuture plans:\n\n* test widgets, push notifications, app extensions, and Firebase,\n* deeplink hijacking,\n* WebView attacks,\n* disassemble, reverse engineer, and resign an IPA,\n* future downgrades using SHSH BLOBS.\n\n## Table of Contents\n\n**-1. [Jailbreaking](#-1-jailbreaking)**\n\n* [Dopamine](#dopamine)\n* [unc0ver](#unc0ver)\n* [3uTools](#3utools)\n\n**0. [Install Tools](#0-install-tools)**\n\n* [Cydia Sources and Tools](#cydia-sources-and-tools)\n* [SSL Kill Switch 2](#ssl-kill-switch-2)\n* [Kali Linux Tools](#kali-linux-tools)\n* [Mobile Security Framework (MobSF)](#mobile-security-framework-mobsf)\n* [Install Web Proxy Certificates](#install-web-proxy-certificates)\n\n**1. [Basics](#1-basics)**\n\n* [Install/Uninstall an IPA](#installuninstall-an-ipa)\n* [SSH to Your iOS Device](#ssh-to-your-ios-device)\n* [Download/Upload Files and Directories](#downloadupload-files-and-directories)\n\n**2. [Inspect an IPA](#2-inspect-an-ipa)**\n\n* [Pull a Decrypted IPA](#pull-a-decrypted-ipa)\n* [Binary](#binary)\n* [Info.plist](#infoplist)\n* [AnyTrans](#anytrans)\n\n**3. [Search for Files and Directories](#3-search-for-files-and-directories)**\n\n* [NSUserDefaults](#nsuserdefaults)\n* [Cache.db](#cachedb)\n\n**4. [Inspect Files](#4-inspect-files)**\n\n* [Single File](#single-file)\n* [Multiple Files](#multiple-files)\n* [File Scraper](#file-scraper)\n* [SQLite 3](#sqlite-3)\n* [Property Lister](#property-lister)\n* [Nuclei](#nuclei)\n* [Backups](#backups)\n\n**5. [Deeplinks](#5-deeplinks)**\n\n**6. [Frida](#6-frida)**\n\n* [Frida Scripts](#frida-scripts)\n\n**7. [Objection](#7-objection)**\n\n* [Bypasses](#bypasses)\n\n**8. [Repackage an IPA](#8-repackage-an-ipa)**\n\n**9. [Miscellaneous](#9-miscellaneous)**\n\n* [Monitor the System Log](#monitor-the-system-log)\n* [Monitor File Changes](#monitor-file-changes)\n* [Dump the Pasteboard](#dump-the-pasteboard)\n* [Get the Provisioning Profile](#get-the-provisioning-profile)\n\n**10. [Tips and Security Best Practices](#10-tips-and-security-best-practices)**\n\n**11. [Useful Websites and Tools](#11-useful-websites-and-tools)**\n\n## -1. Jailbreaking\n\n**Jailbreaking an iOS device will void its warranty. I have no [liability](https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/LICENSE) over your actions.**\n\n### Dopamine\n\nJailbreak your iOS device using [Sideloadly](https://sideloadly.io), [TrollStore](https://github.com/34306/TrollStar), and [Dopamine](https://ellekit.space/dopamine) jailbreak.\n\nMake sure you are logged in to iTunes for Sideloadly to work.\n\nFollow [cfw iOS Guide](https://ios.cfw.guide/installing-trollstore-trollstar) to install TrollStore on your iOS device.\n\nOnce you have sideloaded the IPA, enable the now-visible developer mode in `Settings -\u003e Privacy \u0026 Security -\u003e Developer Mode`.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/dopamine_official_website.png\" alt=\"unc0ver Official Website\" height=\"600em\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 1 - Dopamine Official Website\u003c/p\u003e\n\nDeep linking didn't work for me, so I had to manually install the IPA from a URL in TrollStore.\n\n### unc0ver\n\nJailbreak your iOS device using [AltStore](https://altstore.io) and [unc0ver](https://unc0ver.dev) jailbreak.\n\nFollow [AltStore Docs](https://faq.altstore.io) to install AltStore on your PC.\n\n\\[Optional\\] Fix the sideloading [issue](https://github.com/altstoreio/AltStore/issues/156#issuecomment-717133644) when installing AltStore on your iOS device. You can also use AltStore to install many other cool apps.\n\nOn your iOS device, open Safari, go to [unc0ver.dev](https://unc0ver.dev), and press on `Open in AltStore`. Make sure your antivirus is disabled because it will flag unc0ver IPA as a malware and delete it from your PC.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/unc0ver_official_website.png\" alt=\"unc0ver Official Website\" height=\"600em\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 2 - unc0ver Official Website\u003c/p\u003e\n\nOpen unc0ver, open the settings in the top-left corner, select it as in the image below, and run the jailbreak.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/unc0ver_jailbreaking.png\" alt=\"unc0ver Jailbreak\" height=\"600em\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 3 - unc0ver Jailbreak\u003c/p\u003e\n\n### 3uTools\n\nIf you don't mind sending logs to China, you can also try jailbreaking using [3uTools](https://www.3u.com), it is very easy to use.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/3utools_jailbreaking.jpg\" alt=\"Jailbreaking using 3uTools\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 4 - Jailbreaking using 3uTools\u003c/p\u003e\n\n## 0. Install Tools\n\n### Cydia Sources and Tools\n\nAdd the following sources to Cydia:\n\n* [build.frida.re](https://build.frida.re)\n* [cydia.akemi.ai](https://cydia.akemi.ai)\n* [repo.co.kr](https://repo.co.kr)\n* [havoc.app](https://havoc.app)\n* [julioverne.github.io](https://julioverne.github.io)\n\nInstall required tools on your iOS device using Cydia:\n\n* A-Bypass\n* AppSync Unified\n* Cycript\n* Cydia Substrate\n* Debian Packager\n* Frida \\([fix for v16+ installation issue](https://github.com/frida/frida/issues/2355#issuecomment-1386757290))\n* nano\n* PreferenceLoader\n* ReProvision Reborn\n* SSL Kill Switch 2 (iOS 13)\n* SQLite 3.x\n* wget\n* zip\n\nOver time, some apps might start throwing errors due to the new updates, if reinstalling them using Cydian does not solve the issues, then try to uninstall them completely and install them again.\n\n### SSL Kill Switch 2\n\nThe following project is the original SSL Kill Switch 2 project which is discontinued and not supported on devices with iOS v13 and grater. To download the most up-to-date project, check the [julioverne.github.io](https://julioverne.github.io) repository in Cydia.\n\n[SSH](#ssh-to-your-ios-device) to your iOS device, then, download and install [SSL Kill Switch 2](https://github.com/nabla-c0d3/ssl-kill-switch2/releases):\n\n```fundamental\nwget https://github.com/nabla-c0d3/ssl-kill-switch2/releases/download/0.14/com.nablac0d3.sslkillswitch2_0.14.deb\n\ndpkg -i com.nablac0d3.sslkillswitch2_0.14.deb\n\nkillall -HUP SpringBoard\n```\n\nUninstall SSL Kill Switch 2:\n\n```fundamental\ndpkg -r --force-all com.nablac0d3.sslkillswitch2\n```\n\n### Kali Linux Tools\n\nInstall required tools on your Kali Linux:\n\n```fundamental\napt-get -y install docker.io\n\nsystemctl start docker\n\napt-get -y install ideviceinstaller libimobiledevice-utils libplist-utils nuclei radare2 sqlite3 sqlitebrowser xmlstarlet\n\npip3 install frida-tools objection property-lister file-scraper\n```\n\nMore information about my tools can be found at [ivan-sincek/property-lister](https://github.com/ivan-sincek/property-lister) and [ivan-sincek/file-scraper](https://github.com/ivan-sincek/file-scraper).\n\nMake sure that Frida and Objection are always up to date:\n\n```fundamental\npip3 install --upgrade frida-tools objection\n```\n\n### Mobile Security Framework (MobSF)\n\nInstall:\n\n```fundamental\ndocker pull opensecurity/mobile-security-framework-mobsf\n```\n\nRun:\n\n```fundamental\ndocker run -it --rm --name mobsf -p 8000:8000 opensecurity/mobile-security-framework-mobsf\n```\n\nNavigate to `http://localhost:8000` using your preferred web browser. Username and password are `mobsf:mobsf`.\n\nUninstall:\n\n```fundamental\ndocker image rm opensecurity/mobile-security-framework-mobsf\n```\n\n## Install Web Proxy Certificates\n\nOpen [Burp Suite](https://portswigger.net/burp/communitydownload), navigate to `Proxy --\u003e Proxy Settings` and save the certificate, e.g., as `burp_suite_root_ca.der`.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/exporting_burp_suite_proxy_certificate.png\" alt=\"Exporting Burp Suite Proxy Certificate\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 5 - Exporting Burp Suite Proxy Certificate\u003c/p\u003e\n\nOpen [ZAP](https://www.zaproxy.org), navigate to `Tools --\u003e Options --\u003e Network --\u003e Server Certificates`, and save the certificate, e.g., as `zap_root_ca.cer`.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/exporting_zap_certificate.png\" alt=\"Exporting ZAP Certificate\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 6 - Exporting ZAP Certificate\u003c/p\u003e\n\nOn your Kali Linux, start a local web server, and put the certificates in the web root directory (e.g., `somedir`):\n\n```fundamental\nmkdir somedir\n\npython3 -m http.server 9000 --directory somedir\n```\n\nOn your iOS device, download the certificates with Safari.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/installing_cert_profile.png\" alt=\"Installing a Certificate Profile\" height=\"600em\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 7 - Installing a Certificate Profile\u003c/p\u003e\n\n## 1. Basics\n\n### Install/Uninstall an IPA\n\nInstall an IPA:\n\n```fundamental\nideviceinstaller -i someapp.ipa\n```\n\nUninstall an IPA:\n\n```fundamental\nideviceinstaller -U com.someapp.dev\n```\n\n---\n\nInstall an IPA using [Sideloadly](https://sideloadly.io) desktop app.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/sideloadly_sideloading.jpg\" alt=\"Sideloading an IPA using Sideloadly\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 8 - Sideloading an IPA using Sideloadly\u003c/p\u003e\n\n---\n\nOn your Kali Linux, start a local web server, and put an IPA in the web root directory (e.g., `somedir`):\n\n```fundamental\nmkdir somedir\n\npython3 -m http.server 9000 --directory somedir\n```\n\nOn your iOS device, download the IPA, long press on it, choose \"Share\", and install it using [ReProvision Reborn](https://havoc.app/package/rpr) iOS app. Jailbreak is required.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/reprovision_reborn_sideloading.jpg\" alt=\"Sideloading an IPA using ReProvision Reborn\" height=\"600em\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 9 - Sideloading an IPA using ReProvision Reborn\u003c/p\u003e\n\nIf you have an Apple developer membership, you can code sign your apps for up to 1 year; otherwise, you will need to re-sing them every 7 days.\n\n---\n\nIf you don't mind sending logs to China. Install an IPA using [3uTools](https://www.3u.com) desktop app. Jailbreak is required.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/3utools_sideloading.jpg\" alt=\"Sideloading an IPA using 3uTools\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 10 - Sideloading an IPA using 3uTools\u003c/p\u003e\n\n### SSH to Your iOS Device\n\n```fundamental\nssh root@192.168.1.10\n```\n\nDefault password is `alpine`.\n\n### Download/Upload Files and Directories\n\nTilde `~` is short for the root directory.\n\nDownload a file or directory from your iOS device:\n\n```fundamental\nscp root@192.168.1.10:~/somefile.txt ./\n\nscp -r root@192.168.1.10:~/somedir ./\n```\n\nUpload a file or directory to your iOS device:\n\n```fundamental\nscp somefile.txt root@192.168.1.10:~/\n\nscp -r somedir root@192.168.1.10:~/\n```\n\nUse `nano` to edit files directly on your iOS device.\n\n## 2. Inspect an IPA\n\n### Pull a Decrypted IPA\n\nPull a decrypted IPA from your iOS device:\n\n```bash\ngit clone https://github.com/AloneMonkey/frida-ios-dump \u0026\u0026 cd frida-ios-dump \u0026\u0026 pip3 install -r requirements.txt\n\npython3 dump.py -o decrypted.ipa -P alpine -p 22 -H 192.168.1.10 com.someapp.dev\n```\n\nIf you want to pull an encrypted IPA from your iOS device, see section [9. Repackage an IPA](#8-repackage-an-ipa) and [AnyTrans](#anytrans).\n\nTo unpack, e.g., `someapp.ipa` or `decrypted.ipa` (preferred), run:\n\n```fundamental\nunzip decrypted.ipa\n```\n\nYou should now see the unpacked `Payload` directory.\n\n### Binary\n\nNavigate to `Payload/someapp.app/` directory. There, you will find a binary which have the same name and no file type (i.e., `someapp`).\n\nSearch the binary for specific keywords:\n\n```bash\nrabin2 -zzzqq someapp | grep -Pi 'keyword'\n\nrabin2 -zzzqq someapp | grep -Pi 'hasOnlySecureContent|javaScriptEnabled|UIWebView|WKWebView'\n```\n\nWebViews can sometimes be very subtle, e.g., they could be hidden as a link to terms of agreement, privacy policy, about the software, referral, etc.\n\nSearch the binary for endpoints, deeplinks, sensitive data, comments, etc. For more examples, see section [4. Inspect Files](#4-inspect-files).\n\nSearch the binary for weak hash algorithms, insecure random functions, insecure memory allocation functions, etc. For the best results, use [MobSF](#mobile-security-framework-mobsf).\n\n---\n\nDownload the latest [AppInfoScanner](https://github.com/kelvinBen/AppInfoScanner/releases), install the requirements, and then extract and resolve endpoints from the binary, or directly from the IPA:\n\n```fundamental\npip3 install -r requirements.txt\n\npython3 app.py ios -i someapp\n```\n\n### Info.plist\n\nNavigate to `Payload/someapp.app/` directory. There, you will find a property list file with the name `Info.plist`.\n\nExtract URL schemes from the property list file:\n\n```bash\nxmlstarlet sel -t -v 'plist/dict/array/dict[key = \"CFBundleURLSchemes\"]/array/string' -nl Info.plist 2\u003e/dev/null | sort -uf | tee url_schemes.txt\n```\n\nSearch the property list file for endpoints, sensitive data \\[in Base64 encoding\\], etc. For more examples, see section [4. Inspect Files](#4-inspect-files).\n\n### AnyTrans\n\nExport an IPA using [AnyTrans](https://www.imobie.com/anytrans) desktop app. Excellent for iOS backups too.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/anytrans_download.png\" alt=\"Download an IPA using AnyTrans\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 11 - Download an IPA using AnyTrans\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/anytrans_export.png\" alt=\"Export an IPA using AnyTrans\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 12 - Export an IPA using AnyTrans\u003c/p\u003e\n\n## 3. Search for Files and Directories\n\nSearch for files and directories from the root directory:\n\n```bash\nfind / -iname '*keyword*'\n```\n\nSearch for files and directories in the app specific directories (run `env` in [Objection](#7-objection)):\n\n```bash\ncd /private/var/containers/Bundle/Application/XXX...XXX/\n\ncd /var/mobile/Containers/Data/Application/YYY...YYY/\n```\n\nIf you want to download a whole directory from your iOS device, see section [Download/Upload Files and Directories](#downloadupload-files-and-directories).\n\nI preffer downloading the app specific directories, and then doing the [file inspection](#4-inspect-files) on my Kali Linux.\n\nSearch for files and directories from the current directory:\n\n```bash\nfind . -iname '*keyword*'\n\nfor keyword in 'access' 'account' 'admin' 'card' 'cer' 'conf' 'cred' 'customer' 'email' 'history' 'info' 'json' 'jwt' 'key' 'kyc' 'log' 'otp' 'pass' 'pem' 'pin' 'plist' 'priv' 'refresh' 'salt' 'secret' 'seed' 'setting' 'sign' 'sql' 'token' 'transaction' 'transfer' 'tar' 'txt' 'user' 'zip' 'xml'; do find . -iname \"*${keyword}*\"; done\n```\n\n### NSUserDefaults\n\nSearch for files and directories in [NSUserDefaults](https://developer.apple.com/documentation/foundation/nsuserdefaults) insecure storage directory:\n\n```bash\ncd /var/mobile/Containers/Data/Application/YYY...YYY/Library/Preferences/\n```\n\nSearch for sensitive data in property list files inside NSUserDefaults insecure storage directory:\n\n```fundamental\nscp root@192.168.1.10:/var/mobile/Containers/Data/Application/YYY...YYY/Library/Preferences/com.someapp.dev.plist ./\n\nplistutil -f xml -i com.someapp.dev.plist\n```\n\n### Cache.db\n\nBy default, NSURLSession class stores data such as HTTP requests and responses in Cache.db unencrypted database file.\n\nSearch for sensitive data in property list files inside Cache.db unencrypted database file:\n\n```fundamental\nscp root@192.168.1.10:/var/mobile/Containers/Data/Application/YYY...YYY/Library/Caches/com.someapp.dev/Cache.db ./\n\nproperty-lister -db Cache.db -o plists\n```\n\nCache.db is unencrypted and backed up by default, and as such, should not contain any sensitive data after user logs out - it should be cleared by calling [removeAllCachedResponses\\(\\)](https://developer.apple.com/documentation/foundation/urlcache/1417802-removeallcachedresponses).\n\n## 4. Inspect Files\n\nInspect memory dumps, binaries, files inside [an unpacked IPA](#pull-a-decrypted-ipa), files inside the app specific directories, or any other files.\n\nAfter you finish testing \\[and logout\\], don't forget to [download](#downloadupload-files-and-directories) the app specific directories and inspect all the files inside. Inspect what is new and what still persists after the logout.\n\n**Don't forget to extract Base64 strings from property list files as you might find sensitive data.**\n\nThere will be some false positive results since the regular expressions are not perfect. I prefer to use `rabin2` over `strings` because it can read Unicode characters.\n\nOn your iOS device, try to modify app's files to test the filesystem checksum validation, i.e., to test the file integrity validation.\n\n### Single File\n\nSearch for hardcoded sensitive data:\n\n```bash\nrabin2 -zzzqq somefile | grep -Pi '[^\\w\\d\\n]+(?:basic|bearer)\\ .+'\n\nrabin2 -zzzqq somefile | grep -Pi '(?:access|account|admin|basic|bearer|card|conf|cred|customer|email|history|id|info|jwt|key|kyc|log|otp|pass|pin|priv|refresh|salt|secret|seed|setting|sign|token|transaction|transfer|user)[\\w\\d]*(?:\\\"\\ *\\:|\\ *\\=).+'\n\nrabin2 -zzzqq somefile | grep -Pi '[^\\w\\d\\n]+(?:bug|comment|fix|issue|note|problem|to(?:\\_|\\ |)do|work)[^\\w\\d\\n]+.+'\n```\n\nExtract URLs, deeplinks, IPs, etc.:\n\n```bash\nrabin2 -zzzqq somefile | grep -Po '\\w+\\:\\/\\/[\\w\\-\\.\\@\\:\\/\\?\\=\\%\\\u0026\\#]+' | sort -uf | tee urls.txt\n\nrabin2 -zzzqq somefile | grep -Po '(?:\\b25[0-5]|\\b2[0-4][0-9]|\\b[01]?[0-9][0-9]?)(?:\\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)){3}' | sort -uf | tee ips.txt\n```\n\nExtract all strings and decode Base64 strings:\n\n```bash\nrabin2 -zzzqq somefile | sort -uf \u003e strings.txt\n\ngrep -Po '(?:[a-zA-Z0-9\\+\\/]{4})*(?:[a-zA-Z0-9\\+\\/]{4}|[a-zA-Z0-9\\+\\/]{3}\\=|[a-zA-Z0-9\\+\\/]{2}\\=\\=)' strings.txt | sort -uf \u003e base64.txt\n\nfor string in $(cat base64.txt); do res=$(echo \"${string}\" | base64 -d 2\u003e/dev/null | grep -PI '[\\s\\S]+'); if [[ ! -z $res ]]; then echo -n \"${string}\\n${res}\\n\\n\"; fi; done | tee base64_decoded.txt\n```\n\n### Multiple Files\n\nSearch for hardcoded sensitive data:\n\n```bash\nIFS=$'\\n'; for file in $(find . -type f); do echo -n \"\\nFILE: \\\"${file}\\\"\\n\"; rabin2 -zzzqq \"${file}\" 2\u003e/dev/null | grep -Pi '[^\\w\\d\\n]+(?:basic|bearer)\\ .+'; done\n\nIFS=$'\\n'; for file in $(find . -type f); do echo -n \"\\nFILE: \\\"${file}\\\"\\n\"; rabin2 -zzzqq \"${file}\" 2\u003e/dev/null | grep -Pi '(?:access|account|admin|basic|bearer|card|conf|cred|customer|email|history|id|info|jwt|key|kyc|log|otp|pass|pin|priv|refresh|salt|secret|seed|setting|sign|token|transaction|transfer|user)[\\w\\d]*(?:\\\"\\ *\\:|\\ *\\=).+'; done\n\nIFS=$'\\n'; for file in $(find . -type f); do echo -n \"\\nFILE: \\\"${file}\\\"\\n\"; rabin2 -zzzqq \"${file}\" 2\u003e/dev/null | grep -Pi '[^\\w\\d\\n]+(?:bug|comment|fix|issue|note|problem|to(?:\\_|\\ |)do|work)[^\\w\\d\\n]+.+'; done\n```\n\nExtract URLs, deeplinks, IPs, etc.:\n\n```bash\nIFS=$'\\n'; for file in $(find . -type f); do rabin2 -zzzqq \"${file}\" 2\u003e/dev/null; done | grep -Po '\\w+\\:\\/\\/[\\w\\-\\.\\@\\:\\/\\?\\=\\%\\\u0026\\#]+' | grep -Piv '\\.(css|gif|jpeg|jpg|ogg|otf|png|svg|ttf|woff|woff2)' | sort -uf | tee urls.txt\n\nIFS=$'\\n'; for file in $(find . -type f); do rabin2 -zzzqq \"${file}\" 2\u003e/dev/null; done | grep -Po '(?:\\b25[0-5]|\\b2[0-4][0-9]|\\b[01]?[0-9][0-9]?)(?:\\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)){3}' | sort -uf | tee ips.txt\n```\n\nExtract all strings and decode Base64 strings:\n\n```bash\nIFS=$'\\n'; for file in $(find . -type f); do rabin2 -zzzqq \"${file}\" 2\u003e/dev/null; done | sort -uf \u003e strings.txt\n\ngrep -Po '(?:[a-zA-Z0-9\\+\\/]{4})*(?:[a-zA-Z0-9\\+\\/]{4}|[a-zA-Z0-9\\+\\/]{3}\\=|[a-zA-Z0-9\\+\\/]{2}\\=\\=)' strings.txt | sort -uf \u003e base64.txt\n\nfor string in $(cat base64.txt); do res=$(echo \"${string}\" | base64 -d 2\u003e/dev/null | grep -PI '[\\s\\S]+'); if [[ ! -z $res ]]; then echo -n \"${string}\\n${res}\\n\\n\"; fi; done | tee base64_decoded.txt\n```\n\n### File Scraper\n\nAutomate all of the above file inspection (and more) with a single tool, also using multithreading.\n\n```bash\napt-get -y install radare2\n\npip3 install file-scraper\n```\n  \n```fundamental\nfile-scraper -dir Payload -o results.html -e default\n```\n\nMore about my other project at [ivan-sincek/file-scraper](https://github.com/ivan-sincek/file-scraper).\n\n### SQLite 3\n\nUse [SCP](#downloadupload-files-and-directories) to download database files, and then open them using [DB Browser for SQLite](https://sqlitebrowser.org).\n\nTo inspect the content, navigate to `Browse Data` tab, expand `Table` dropdown menu, and select the desired table.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/sqlite.png\" alt=\"SQLite\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 13 - DB Browser for SQLite\u003c/p\u003e\n\nTo inspect/edit database files on your iOS device, use [SQLite 3](#cydia-sources-and-tools); [SSH](#ssh-to-your-ios-device) to your iOS device and run the following commands:\n\n```sql\nsqlite3 somefile\n\n.dump\n\n.tables\n\nSELECT * FROM sometable;\n\n.quit\n```\n\n[Property Lister](#property-lister) will dump all databases in plain-text automatically.\n\n### Property Lister\n\nUnpack, e.g., `someapp.ipa` or [decrypted.ipa](#pull-a-decrypted-ipa) (preferred).\n\nDump all the databases, and extract and convert all the property list files inside an IPA:\n\n```fundamental\nproperty-lister -db Payload -o results_db\n\nproperty-lister -pl Payload -o results_pl\n```\n\nRepeat the same for [the app specific directories](#3-search-for-files-and-directories).\n\nMore about my other project at [ivan-sincek/property-lister](https://github.com/ivan-sincek/property-lister).\n\n### Nuclei\n\nDownload mobile Nuclei templates:\n\n```fundamental\ngit clone https://github.com/optiv/mobile-nuclei-templates ~/mobile-nuclei-templates\n```\n\nUnpack, e.g., `someapp.ipa` or [decrypted.ipa](#pull-a-decrypted-ipa) (preferred).\n\nSearch for hardcoded sensitive data:\n\n```bash\necho Payload | nuclei -t ~/mobile-nuclei-templates/Keys/ -o nuclei_keys_results.txt\n\ncat nuclei_keys_results.txt | grep -Po '(?\u003c=\\]\\ ).+' | sort -uf \u003e nuclei_keys_results_sorted.txt\n```\n\n### Backups\n\nGet your iOS device UDID:\n\n```fundamental\nidevice_id -l\n```\n\nCreate a backup:\n\n```bash\nidevicebackup2 backup --full -u $(idevice_id -l) ./backup\n```\n\nApp should not backup any sensitive data.\n\nRestore from a backup:\n\n```bash\nidevicebackup2 restore -u $(idevice_id -l) ./backup\n```\n\n---\n\nBrowse backups using [iExplorer](https://macroplant.com/iexplorer) (demo) for Windows OS. There are many other iOS backup tools, but they cannot browse app specific directories.\n\niExplorer's default directory for storing iOS backups:\n\n```fundamental\nC:\\Users\\%USERNAME%\\AppData\\Roaming\\Apple Computer\\MobileSync\\Backup\\\n```\n\nYou can place your backups in either this directory or change it in settings.\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/iexplorer.png\" alt=\"iExplorer\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 14 - iExplorer\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"https://github.com/ivan-sincek/ios-penetration-testing-cheat-sheet/blob/main/img/iexplorer_browse.png\" alt=\"Browse a backup using iExplorer\"\u003e\u003c/p\u003e\n\n\u003cp align=\"center\"\u003eFigure 15 - Browse a backup using iExplorer\u003c/p\u003e\n\n## 5. Deeplinks\n\nTest [/.well-known/apple-app-site-association](https://developer.apple.com/documentation/xcode/supporting-associated-domains) using [branch.io/resources/aasa-validator](https://branch.io/resources/aasa-validator).\n\nSometimes, deeplinks can bypass authentication, including biometrics.\n\nCreate an HTML template to manually test deeplinks:\n\n```bash\nmkdir ios_deeplinks\n\n# multiple URL schemes\n\nfor scheme in $(cat url_schemes.txt); do for url in $(cat urls.txt | grep -Poi \"${scheme}\\:\\/\\/.+\"); do if [[ ! -z $url ]]; then echo -n \"\u003ca href='${url}'\u003e${url}\u003c/a\u003e\\n\u003cbr\u003e\u003cbr\u003e\\n\" | tee -a \"ios_deeplinks/${scheme}_deeplinks.html\"; fi; done; done\n\n# single URL scheme\n\nscheme=\"somescheme\"; for string in $(cat urls.txt | grep -Poi \"${scheme}\\:\\/\\/.+\"); do echo -n \"\u003ca href='${string}'\u003e${string}\u003c/a\u003e\\n\u003cbr\u003e\u003cbr\u003e\\n\"; done | tee -a \"ios_deeplinks/${scheme}_deeplinks.html\"\n\npython3 -m http.server 9000 --directory ios_deeplinks\n```\n\nFor `url_schemes.txt` see section [Info.plist](#infoplist), and for `urls.txt` see section [4. Inspect Files](#4-inspect-files).\n\n---\n\nFuzz deeplinks using [ios-deeplink-fuzzing](https://codeshare.frida.re/@ivan-sincek/ios-deeplink-fuzzing) script with [Frida](#6-frida):\n\n```fundamental\nfrida -U -no-pause -l ios-deeplink-fuzzing.js -f com.someapp.dev\n\nfrida -U -no-pause --codeshare ivan-sincek/ios-deeplink-fuzzing -f com.someapp.dev\n```\n\nCheck the source code for more instructions. You can also paste the whole source code directly into Frida and call the methods as you prefer.\n\n## 6. Frida\n\nUseful resources:\n\n* [frida.re](https://frida.re/docs/home)\n* [learnfrida.info](https://learnfrida.info)\n* [codeshare.frida.re](https://codeshare.frida.re)\n* [dweinstein/awesome-frida](https://github.com/dweinstein/awesome-frida)\n* [interference-security/frida-scripts](https://github.com/interference-security/frida-scripts)\n* [m0bilesecurity/Frida-Mobile-Scripts](https://github.com/m0bilesecurity/Frida-Mobile-Scripts)\n\nList processes:\n\n```bash\nfrida-ps -Uai\n\nfrida-ps -Uai | grep -i 'keyword'\n```\n\nGet PID for a specified keyword:\n\n```bash\nfrida-ps -Uai | grep -i 'keyword' | cut -d ' ' -f 1\n```\n\nDiscover internal methods/calls:\n\n```bash\nfrida-discover -U -f com.someapp.dev | tee frida_discover.txt\n```\n\nTrace internal methods/calls:\n\n```bash\nfrida-trace -U -p 1337\n\nfrida-trace -U -p 1337 -i 'recv*' -i 'send*'\n```\n\n### Frida Scripts\n\nBypass biometrics using [ios-touch-id-bypass](https://codeshare.frida.re/@ivan-sincek/ios-touch-id-bypass) script:\n\n```fundamental\nfrida -U -no-pause -l ios-touch-id-bypass.js -f com.someapp.dev\n\nfrida -U -no-pause --codeshare ivan-sincek/ios-touch-id-bypass -f com.someapp.dev\n```\n\nOn the touch ID prompt, press `Cancel`.\n\nI prefer to use the built-in method in [Objection](#bypasses).\n\n---\n\nHook all classes and methods using [ios-hook-classes-methods](https://codeshare.frida.re/@ivan-sincek/ios-hook-classes-methods) script:\n\n```fundamental\nfrida -U -no-pause -l ios-hook-classes-methods.js -f com.someapp.dev\n\nfrida -U -no-pause --codeshare ivan-sincek/ios-hook-classes-methods -f com.someapp.dev\n```\n\n## 7. Objection\n\nUseful resources:\n\n* [sensepost/objection](https://github.com/sensepost/objection)\n\nRun:\n\n```fundamental\nobjection -g com.someapp.dev explore\n```\n\nRun a [Frida](#6-frida) script in Objection:\n\n```fundamental\nimport somescript.js\n\nobjection -g com.someapp.dev explore --startup-script somescript.js\n```\n\nGet information:\n\n```fundamental\nios info binary\n\nios plist cat Info.plist\n```\n\nGet environment variables:\n\n```fundamental\nenv\n```\n\nGet HTTP cookies:\n\n```fundamental\nios cookies get\n```\n\nDump Keychain, NSURLCredentialStorage, and NSUserDefaults:\n\n```fundamental\nios keychain dump\n\nios nsurlcredentialstorage dump\n\nios nsuserdefaults get\n```\n\nSensitive data such as app's PIN, password, etc., should not be stored as a plain-text in the keychain; instead, they should be hashed as an additional level of protection.\n\nDump app's memory to a file:\n\n```fundamental\nmemory dump all mem.dmp\n```\n\nDump app's memory after, e.g., 10 minutes of inactivity, then, check if sensitive data is still in the memory, see section [4. Inspect Files](#4-inspect-files).\n\n**In case Objection detaches from the app, use the process ID to attach it back without restarting the app.**\n\nSearch app's memory directly:\n\n```bash\nmemory search 'somestring' --string\n```\n\nList classes and methods:\n\n```bash\nios hooking list classes\nios hooking search classes 'keyword'\n\nios hooking list class_methods 'someclass'\nios hooking search methods 'keyword'\n```\n\nHook on a class or method:\n\n```bash\nios hooking watch class 'someclass'\n\nios hooking watch method '-[someclass somemethod]' --dump-args --dump-backtrace --dump-return\n```\n\nChange the method's return value:\n\n```bash\nios hooking set return_value '-[someclass somemethod]' false\n```\n\nMonitor crypto libraries:\n\n```fundamental\nios monitor crypto\n```\n\nMonitor the pasteboard:\n\n```fundamental\nios pasteboard monitor\n```\n\nYou can also dump the pasteboard using [cycript](#dump-the-pasteboard).\n\n### Bypasses\n\nBypass a jailbreak detection:\n\n```bash\nios jailbreak disable --quiet\n\nobjection -g com.someapp.dev explore --startup-command 'ios jailbreak disable --quiet'\n```\n\nAlso, on your iOS device, check `A-Bypass` in `Settings` app.\n\n---\n\nBypass SSL pinning:\n\n```bash\nios sslpinning disable --quiet\n\nobjection -g com.someapp.dev explore --startup-command 'ios sslpinning disable --quiet'\n```\n\nAlso, on your iOS device, check [SSL Kill Switch 2](#ssl-kill-switch-2) in `Settings` app.\n\n---\n\nBypass biometrics:\n\n```bash\nios ui biometrics_bypass --quiet\n\nobjection -g com.someapp.dev explore --startup-command 'ios ui biometrics_bypass --quiet'\n```\n\nAlso, you can import [Frida](#frida-scripts) script.\n\n## 8. Repackage an IPA\n\n[SSH](#ssh-to-your-ios-device) to your iOS device and run the following commands.\n\nNavigate to the app specific directory:\n\n```bash\ncd /private/var/containers/Bundle/Application/XXX...XXX/\n```\n\nRepackage the IPA:\n\n```fundamental\nmkdir Payload\n\ncp -r someapp.app Payload\n\nzip -r repackaged.ipa Payload\n\nrm -rf Payload\n```\n\nOn your Kali Linux, download the repackaged IPA:\n\n```fundamental\nscp root@192.168.1.10:/private/var/containers/Bundle/Application/XXX...XXX/repackaged.ipa ./\n```\n\nIf you want to pull a decrypted IPA from your iOS device, see section [Pull a Decrypted IPA](#pull-a-decrypted-ipa).\n\n## 9. Miscellaneous\n\n### Monitor the System Log\n\nOn your Kali Linux, run the following command:\n\n```fundamental\nidevicesyslog -p 1337\n```\n\nOr, get the PID from a keyword:\n\n```fundamental\nkeyword=\"keyword\"; idevicesyslog -p $(frida-ps -Uai | grep -i \"${keyword}\" | tr -s '[:blank:]' ' ' | cut -d ' ' -f 1)\n```\n\n### Monitor File Changes\n\n[SSH](#ssh-to-your-ios-device) to your iOS device, then, download and run [Filemon](http://www.newosxbook.com):\n\n```bash\nwget http://www.newosxbook.com/tools/filemon.tgz \u0026\u0026 tar zxvf filemon.tgz \u0026\u0026 chmod +x filemon\n\n./filemon -c -f com.someapp.dev\n```\n\nAlways look for created or cached files, images/screenshots, etc. Use `nano` to edit files directly on your iOS device.\n\nSensitive files such as know your customer (KYC) and similar, should not persists in the app specific directories on user's device after the file upload. Sensitive files should not be stored in `/tmp/` directory nor similar system-wide directories.\n\nImages and screenshots path:\n\n```fundamental\ncd /var/mobile/Containers/Data/Application/YYY...YYY/Library/SplashBoard/Snapshots/\n```\n\n### Dump the Pasteboard\n\nAfter copying sensitive data, the app should wipe the pasteboard after a short period of time.\n\n[SSH](#ssh-to-your-ios-device) to your iOS device and run the following commands:\n\n```fundamental\ncycript -p 1337\n\n[UIPasteboard generalPasteboard].items\n```\n\nPress `CTRL + D` to exit.\n\nYou can also monitor the pasteboard in [Objection](#7-objection).\n\n### Get the Provisioning Profile\n\n```fundamental\nscp root@192.168.1.10:/private/var/containers/Bundle/Application/XXX...XXX/*.app/embedded.mobileprovision ./\n\nopenssl smime -inform der -verify -noverify -in embedded.mobileprovision\n```\n\n## 10. Tips and Security Best Practices\n\nBypass any keyboard restriction by copying and pasting data into an input field.\n\nAccess tokens should be short lived, and if possible, invalidated on logout.\n\nDon't forget to test widgets, push notifications, app extensions, and Firebase.\n\nSometimes, deeplinks and widgets can bypass authentication, including biometrics.\n\nOnly if explicitly allowed, try flooding 3rd party APIs to cause possible monetary damage to the company, or denial-of-service (DoS) by exhausting the allowed quotas/limits.\n\n---\n\nApp should not disclose sensitive data in the predictive text (due to incorrectly defined input field type), app switcher, and push notifications.\n\nApp should warn a user when taking a screenshot of sensitive data.\n\nApp should warn a user that it is trivial to bypass biometrics authentication if iOS device is jailbroken.\n\nProduction app (i.e., build) should not be debuggable.\n\n## 11. Useful Websites and Tools\n\n| URL | Description |\n| --- | --- |\n| [developer.apple.com/account](https://developer.apple.com/account) | Official iOS documentation, create code signing certificates, etc. |\n| [developer.apple.com/apple-pay/sandbox-testing](https://developer.apple.com/apple-pay/sandbox-testing) | Test debit/credit cards for Apple Pay. |\n| [streaak/keyhacks](https://github.com/streaak/keyhacks) | Validate various API keys. |\n| [zxing.org/w/decode.jspx](https://zxing.org/w/decode.jspx) | Decode QR codes. |\n| [youtube.com/user/iDeviceMovies](https://www.youtube.com/user/iDeviceMovies) | Useful videos about jailbreaking, etc. |\n| [ipsw.me/product/iPhone](https://ipsw.me/product/iPhone) | Firmwares for Apple devices. |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fivan-sincek%2Fios-penetration-testing-cheat-sheet","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fivan-sincek%2Fios-penetration-testing-cheat-sheet","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fivan-sincek%2Fios-penetration-testing-cheat-sheet/lists"}