Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/satan1a/awesome-ios-security-cn

iOS安全资料整理(中文)
https://github.com/satan1a/awesome-ios-security-cn

List: awesome-ios-security-cn

awesome ios-security mobile-security

Last synced: about 1 month ago
JSON representation

iOS安全资料整理(中文)

Awesome Lists containing this project

README

        

# iOS安全资料整理

iOS安全是一个不错的安全研究方向,但中文的资料与整理还是比较缺乏的,因此开启这个awesome清单,欢迎大家来一起贡献!

## 书籍📚

- 《九阴真经·iOS黑客攻防秘籍》,陈德,[博客](https://www.exchen.net/)
- 《 iOS应用逆向与安全之道》,罗巍,网名飘云,“飘云阁安全论坛”创始人
- 《iOS应用逆向与安全》,刘培庆
- 《iOS应用逆向工程》,沙梓社、吴航
- 《iOS 13 App程式设计实战心法》,来自台湾翻译,是最新的Swift5 + Xcode11:[GitBook](https://www.appcoda.com.tw/learnswift/get-started.html),[英文原版](https://www.appcoda.com/learnswift/get-started.html)
- 《iOS安全wiki》,GitBook:[Link](https://wizardforcel.gitbooks.io/ios-sec-wiki/content/chapter1/issue1-1.html)

## 博客

- iOS底层知识&汇编&逆向,IIronMan:[Link](https://www.jianshu.com/nb/25543579)

- exchen,《九阴真经 iOS黑客攻防秘籍》作者的博客:[Link](https://www.exchen.net/)

- iOS开发小分队技术分享团队博客:[Link](http://justdoios.club/)

- Hook|潜心习安全:[Link](https://gloxec.github.io/)

- wg689,简书博客:[Link](https://www.jianshu.com/u/e03c395306c5)

- 颜值不够才华来凑,简书:[Link](https://www.jianshu.com/u/ff864c7a8f24)

## 论坛

- 看雪,iOS安全小组:[Link](https://bbs.pediy.com/thread-212685.htm)
- FreeBuf, iOS板块: [Link]([https://www.freebuf.com/tag/ios%e5%ae%89%e5%85%a8](https://www.freebuf.com/tag/ios安全))
- 52pojie,移动安全板块,iOS文章:[Link](https://www.52pojie.cn/forum.php?mod=forumdisplay&fid=65&filter=typeid&typeid=195)
- iOS安全论坛,ioshacker.net:[Link](https://www.ioshacker.net/forum-38-1.html)
- 飘云阁,《 iOS应用逆向与安全之道》作者的论坛:[Link](https://www.chinapyg.com/thread-135989-1-1.html)

## 工具

- Frida(frida, frida-tools):[Link](https://frida.re/)
- Lookin,腾讯开发,类似Reveal:[Link](https://lookin.work/)
- Hopper Disassembler,macOS和Linux反汇编程序:[Link](https://www.hopperapp.com/)
- IPA的获取方法和工具:[Link](https://www.jianshu.com/p/73e65b0a9b86)
- Appsync-Unified,IPA安装文件面验证,在iOS13上安装教程:[Link](https://kubadownload.com/news/appsync-unified)
- KubaDownload, 有一些较新Cydia软件的下载站:[Link](https://kubadownload.com/)
- Filza,功能强大的iOS文件管理器,适配iOS13:[Link](https://kubadownload.com/news/filza-file-manager)
- Clutch,[脱壳](https://www.jianshu.com/p/79d2d9f3958c)工具,比较经典,但现在有需要应用都无法用其脱壳:[Link](https://github.com/KJCracks/Clutch)
- dumpdecrypted,脱壳工具:[Link](https://github.com/stefanesser/dumpdecrypted/)
- Object, 基于Frida的一个注入框架:[Link](https://github.com/sensepost/objection)

## 漏洞研究

- 《远程iPhone Exploitation Part 1:iMessage与CVE-2019-8641》:[Link](远程iPhone Exploitation Part 1:iMessage与CVE-2019-8641)

## 开源资料

- https://github.com/vaib25vicky/awesome-mobile-security
- https://github.com/vsouza/awesome-ios
- https://github.com/ashishb/osx-and-ios-security-awesome
- https://github.com/ansjdnakjdnajkd/iOS
- https://github.com/ivRodriguezCA/RE-iOS-Apps
- https://github.com/felixgr/secure-ios-app-dev
- https://github.com/kai5263499/osx-security-awesome
- https://wizardforcel.gitbooks.io/ios-sec-wiki/

## 清单

- Awesome iOS Application Security,可以看看里面整理的工具清单,比较全:[Link](https://enciphers.com/awesome-ios-application-security/)
- NowSecure的移动应用安全指南:[Link](https://books.nowsecure.com/secure-mobile-development/en/android/use-broadcasts-carefully.html)

## 官方

- Xcode + Swift:[Link](https://developer.apple.com/swift/resources/)

- Swift:[Link](https://developer.apple.com/videos/developer-tools/swift/)

## 开发相关

- 在写一个iOS应用之前必须做的7件事:[Link]()
- iOS大牛技术博客收藏贴:[Link](https://www.jianshu.com/p/c55c6b30ef28)
- 知乎专栏上的一个iOS开发学习清单:[Link](https://zhuanlan.zhihu.com/p/53217607)
- 从零开始学iOS7开发系列教程,王寒对iOS Appreciate的翻译:[Link](https://zhuanlan.zhihu.com/p/19652676)

## TODO

- iOS Penetration Testing:[Google](https://www.google.com/search?sxsrf=ALeKk02TTUXqUJzUP1Q6hwYBk5JEFdE6eA%3A1582972724188&source=hp&ei=ND9aXrqRCLXLmAWYgJxo&q=ios+penetration+testing&oq=iOS+pene&gs_l=psy-ab.3.0.0l7j0i22i30l3.596.2175..4044...1.0..0.559.2170.0j7j4-1j1......0....1..gws-wiz.......35i39j0i67j0i131j0i20i263j0i203.Iyfm2VOKTPE)