Os Security The complete iOS Pentesting & Bug Bounty Course

HackingAssets

Member
Lucifer
Joined
Aug 12, 2022
Messages
163
Hellcoins
♆1,596
Username Style (Gradient Colours)

Course content:​

Introduction​

  • Introduction
  • Disclaimer

Setting Up your hacking environment!​

  • Setting up Mobexler
  • Setting up MacOS on Windows Machine
  • Simulators
  • Emulators
  • Jailbreaking and its types
  • Jailbreaking Practical
  • Jailbreaking Practical Update - NEW
  • Connecting Burp Suite with iOS Device

Getting Started with iOS​

  • Introduction to iOS Applications
  • Introduction to Info.plist files
  • What is UDID?
  • Accessing the device shell
  • On-device Shell App
  • Transferring data between device and PC
  • Extracting and Decrypting IPAs using frida-ios-dump
  • Extracting and Decrypting IPAs using Filza
  • Extracting and Decrypting IPAs using iMazing
  • Installing Applications using 3uTools
  • Installing Applications by Sideloading method

iOS basics​

  • Data Protection
  • Keychain
  • App Capabilties and Purpose Strings
  • App Extensions
  • Device Management

OWASP Mobile Top 10​

  • What is OWASP?
  • M1: Improper Platform Usage
  • M2: Insecure Data Storage
  • M3: Insecure Communication & M4: Insecure Authentication
  • M5: Insufficient Cryptography
  • OWASP M6, M7, M8, M9, M10

Static Analysis​

  • MobSF
  • File System Analysis
  • Application Log Analysis
  • Hardcoded Credentials
  • SQLite Databases
  • Other Databases
  • Firebase Misconfigurations
  • iOS Keychain
  • iOS UIPasteboard
  • iOS WebViews
  • Application Patching
  • Sensitive information inside Applications Memory
  • Insecure APIs/Functions

Dynamic Analysis​

  • Tweaks, Substitute, Cydia/Sileo & Installing your first tweak!
  • Installing Frida
  • What is Jailbreak Detection? & Jailbreak Detection Bypass using Frida
  • Jailbreak Detection Bypass using Shadow
  • Jailbreak Detection Bypass using Liberty
  • Jailbreak Detection Bypass using A-Bypass
  • Jailbreak Detection Bypass using Objection
  • Other Utilities
  • What is SSL Pinning? & SSL Pinning Bypass using Frida
  • SSL Pinning Bypass using SSL Kill Switch
  • SSL Pinning Bypass using Objection
  • Local Authentication Mechanisms Bypass

Live Attack on a Bug Bounty Program (99 Acres)​

  • Disclaimer
  • Live Demo

Tips & Tricks​

  • iOS Pentesting Checklist
  • iOS Pentesting Mindmap
  • iOS Pentesting Nuclei Templates
  • iOS Pentesting Reports
  • Using Objection and Frida without Jailbreaking the device
  • iOS Hacking Reports
  • iOS Frida Scripts

Bonus Lecture: Conclusion & Links​

  • Conclusion
  • Links
Download & Mega Link:
 
Last edited by a moderator:
Top