Track 05 · iOS Application Pentesting

Run a professional iOS application assessment from IPA to final report.

Work through a complete black-box assessment of MediVault using a controlled iOS research guest, Burp, Frida, static analysis, runtime instrumentation, storage review, IPC testing, RASP bypass, client-side patching, and reproducible evidence.

Full access includes the intentionally vulnerable MediVault IPA, matching Swift source, and the reusable course script library. Lab packages remain protected by the course entitlement.

$499$399 offer
00

Workbench: vPhone, Burp, Frida

Stand up a jailbroken virtual iPhone, SSH into /var/jb, and put Burp and Frida 17 on the wire.

7 modules
00.1Course introduction: the iOS application pentest
Free preview
00.2Host requirements: Apple Silicon, SIP, AMFI, Burp, and Frida 17
Locked
00.3The lab guest: iOS 26.1, jb variant, and research identity
Locked
00.4SSH and PATH: stock login PATH versus /var/jb
Locked
00.5Guest packages: Sileo, TrollStore Lite, and the TweakLoader rule
Locked
00.6Frida-server: LaunchDaemons rejected, nohup after boot
Locked
00.7Guest proxy, Burp listener, CA, and intercept
Locked
01

Engagement model and the iOS security stack

Scope the assessment, then read AMFI, signing, and the sandbox from the guest CLI.

4 modules
01.1The assessment you were hired to run: scope, claim ladder, and evidence
Locked
01.2AMFI, code signing, and launch constraints from sysctl and ioreg
Locked
01.3Sandbox and container layout on a jailbroken guest
Locked
01.4Simulator vs vphone vs stock iPhone: what each environment actually tests
Locked
02

Static: the IPA before it runs

Read MediVault as a bundle: entitlements, strings, pins, CoreML, and the attack-surface map.

7 modules
02.1IPA anatomy: Payload, Info.plist, and embedded.mobileprovision
Locked
02.2Entitlements and the capability attack surface
Locked
02.3Privacy manifest and TCC usage strings
Locked
02.4Mach-O, symbols, Swift metadata, and strings
Locked
02.5Hardcoded endpoints, placeholder pins, and secret triage
Locked
02.6Third-party SDK and CoreML model inventory
Locked
02.7Static attack-surface map for MediVault
Locked
03

Network: Burp on a jailbroken iOS 26 device

Proxy at boot, kill pinning two ways, and stay honest about the mock backend.

6 modules
03.1Guest proxy persistence and SSL Kill Switch 3 via plist
Locked
03.2Mapping MediVault traffic: pinned API vs unpinned telemetry
Locked
03.3Pinning identification from static and runtime
Locked
03.4Bypass with SSL Kill Switch 3, then with Frida
Locked
03.5Request manipulation against the mock backend
Locked
03.6Network findings writeup: placeholder pins, cleartext telemetry, mock auth
Locked
04

Runtime: change what the running app believes

Typical iOS functions, then Frida, Objection, and the other runtime tactics a tester uses to exploit them.

10 modules
04.1What runtime exploitation is for: typical iOS functions, objective, exploit, evidence
Locked
04.2Frida 17 on this guest: attach, spawn, and the ObjC bridge
Locked
04.3Find the functions that implement those features
Locked
04.4Bypass jailbreak and environment checks
Locked
04.5Bypass login, session, and the biometric UX gate
Locked
04.6Bypass pinning and dump live secrets
Locked
04.7Objection: first-hour commands mapped to those exploits
Locked
04.8frida-trace, heap instances, and codeshare discipline
Locked
04.9Other runtime tactics: debugserver, tweaks, Gadget, and Web Inspector
Locked
04.10Runtime evidence pack for the rest of the engagement
Locked
05

Data at rest

Walk the container as mobile and as root. SQLite, keychain, snapshots, file protection.

8 modules
05.1Container walk as mobile and as root
Locked
05.2UserDefaults, App Group suite, and planted session/MRN/NPI
Locked
05.3CoreData / SQLite patient records
Locked
05.4Keychain dump: Frida and sqlite3 on keychain-2.db
Locked
05.5Snapshots, pasteboard residue, and unified logs
Locked
05.6File protection classes: jb reads everything; stock does not
Locked
05.7Data-at-rest findings table
Locked
05.8Unencrypted backup parse: Manifest.db method
Locked
06

Authentication and cryptography

Mock login, LAContext vs Keychain ACL, App Attest as an honest negative.

5 modules
06.1Mock login, session tokens, and expiry that is never checked
Locked
06.2LAContext as a UX gate vs Keychain ACL as a crypto gate
Locked
06.3Bypassing the biometric prompt at evaluatePolicy
Locked
06.4App Attest / DeviceCheck: capability and research-VM failure
Locked
06.5Crypto primitive identification and the medication-key finding
Locked
07

IPC and WebView

uiopen schemes, App Group writes, pasteboard, WKWebView bridges that leak PHI.

6 modules
07.1URL scheme map and uiopen --url / --bundleid
Locked
07.2Injecting a session token across the app boundary
Locked
07.3App Group write attack
Locked
07.4Pasteboard exposure window
Locked
07.5WKWebView security model and bridge enumeration
Locked
07.6Calling patientDataHandler and sessionManager from injected JS
Locked
08

RASP and jailbreak detection

Map MediVault detectors, bypass without touching __TEXT, inject with opainject, triage crashes.

9 modules
08.1Detector map: what is watching you
Locked
08.2Debugger, Frida-port, and dylib checks
Locked
08.3Checksum and prologue: why inline hooks get you caught
Locked
08.4Non-inline bypass (fishhook / ElleKit) and late injection
Locked
08.5Telemetry suppression without breaking the pinned API client
Locked
08.6Writing a tiny ElleKit tweak
Locked
08.7opainject pid dylib when Frida is the alarm
Locked
08.8Crash .ips triage after a bad hook or a bad patch
Locked
08.9Claim ladder for RASP findings
Locked
09

Client-side patching

Dump, byte-patch, survive CODE_PAGE_MODIFIED, insert_dylib, embed Frida Gadget.

8 modules
09.1Hook vs patch vs tweak vs Gadget
Locked
09.2Dump / decrypt a FairPlay IPA on jb vs the unsigned lab IPA
Locked
09.3Find the patch site: jb check, pin compare, RASPEngine.initialize
Locked
09.4Byte patch + ldid + TrollStore, then watch CODE_PAGE_MODIFIED
Locked
09.5Integrity-aware patching
Locked
09.6insert_dylib: payload constructor dylib
Locked
09.7Embed Frida Gadget, rename it, connect without frida-server
Locked
09.8Script library and the stock path: resign + Gadget
Locked
10

Evidence, report, capstone

Replayable evidence, CVSS-mobile, the full MediVault finding set, and a delivered report.

7 modules
10.1Evidence that another tester can replay
Locked
10.2CVSS for mobile and finding classification
Locked
10.3Writing findings that get fixed
Locked
10.4The complete MediVault finding set with claim rungs
Locked
10.5Scope limitations: vphone, mock backend, App Attest, SEP
Locked
10.6Capstone: full assessment of MediVault
Locked
10.7When the next IPA is not MediVault: FairPlay, TrustKit, OAuth
Locked