iOS Pentesting without Jailbreak

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Main idea

get_task_allow ๊ถŒํ•œ์œผ๋กœ ์„œ๋ช…๋œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ํƒ€์‚ฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด **task_for_pid()**๋ผ๋Š” ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•˜๋ฉฐ, ์ด ํ•จ์ˆ˜๋Š” ์ดˆ๊ธฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ํ”„๋กœ์„ธ์Šค ID๋ฅผ ์ธ์ˆ˜๋กœ ๋ฐ›์•„ ํ•ด๋‹น ์ž‘์—… ํฌํŠธ๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค(์ œ์–ดํ•˜๊ณ  ๋ฉ”๋ชจ๋ฆฌ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋จ).

ํ•˜์ง€๋งŒ IPA๋ฅผ ๊ฐ€์ ธ์™€์„œ ๊ถŒํ•œ์œผ๋กœ ์žฌ์„œ๋ช…ํ•œ ํ›„ ์žฅ์น˜์— ๋‹ค์‹œ ํ”Œ๋ž˜์‹œํ•˜๋Š” ๊ฒƒ์€ ๊ทธ๋ฆฌ ๊ฐ„๋‹จํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด๋Š” FairPlay ๋ณดํ˜ธ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ์•ฑ์˜ ์„œ๋ช…์ด ๋ณ€๊ฒฝ๋˜๋ฉด DRM(๋””์ง€ํ„ธ ๊ถŒ๋ฆฌ ๊ด€๋ฆฌ) ํ‚ค๊ฐ€ ๋ฌดํšจํ™”๋˜๋ฉฐ ์•ฑ์ด ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๊ตฌํ˜• ํƒˆ์˜ฅ๋œ ์žฅ์น˜์—์„œ๋Š” IPA๋ฅผ ์„ค์น˜ํ•˜๊ณ , ์ข‹์•„ํ•˜๋Š” ๋„๊ตฌ(์˜ˆ: Iridium ๋˜๋Š” frida-ios-dump)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณตํ˜ธํ™”ํ•œ ํ›„ ์žฅ์น˜์—์„œ ๋‹ค์‹œ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ€๋Šฅํ•˜๋‹ค๋ฉด ๋ณตํ˜ธํ™”๋œ IPA๋ฅผ ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์š”์ฒญํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

Obtain decrypted IPA

Get it from Apple

  1. iPhone์— ํŽœํ…Œ์ŠคํŠธํ•  ์•ฑ์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.
  2. macOS์—์„œ Apple Configurator๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  3. Mac์—์„œ Terminal์„ ์—ด๊ณ  /Users/[username]/Library/Group\\ Containers/K36BKF7T3D.group.com.apple.configurator/Library/Caches/Assets/TemporaryItems/MobileApps๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ๋‚˜์ค‘์— ์ด ํด๋”์— IPA๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.
  4. iOS ์žฅ์น˜๊ฐ€ ํ‘œ์‹œ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋”๋ธ” ํด๋ฆญํ•œ ํ›„ ์ƒ๋‹จ ๋ฉ”๋‰ด ๋ฐ”์—์„œ Add + โ†’ Apps๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  5. Add๋ฅผ ํด๋ฆญํ•˜๋ฉด Configurator๊ฐ€ Apple์—์„œ IPA๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์žฅ์น˜์— ํ‘ธ์‹œํ•˜๋ ค๊ณ  ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค. ์ด์ „์— ์ œ ์ถ”์ฒœ์„ ๋”ฐ๋ฅด๊ณ  IPA๋ฅผ ์ด๋ฏธ ์„ค์น˜ํ–ˆ๋‹ค๋ฉด ์•ฑ์„ ์žฌ์„ค์น˜ํ•˜๋ผ๋Š” ํ”„๋กฌํ”„ํŠธ๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.
  6. IPA๋Š” /Users/[username]/Library/Group\\ Containers/K36BKF7T3D.group.com.apple.configurator/Library/Caches/Assets/TemporaryItems/MobileApps์— ๋‹ค์šด๋กœ๋“œ๋˜๋ฉฐ, ์—ฌ๊ธฐ์„œ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ํ”„๋กœ์„ธ์Šค์— ๋Œ€ํ•œ ๋” ์ž์„ธํ•œ ์ •๋ณด๋Š” https://dvuln.com/blog/modern-ios-pentesting-no-jailbreak-needed๋ฅผ ํ™•์ธํ•˜์„ธ์š”.

Decrypting the app

IPA๋ฅผ ๋ณตํ˜ธํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์„ค์น˜ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ตฌํ˜• ํƒˆ์˜ฅ๋œ iPhone์ด ์žˆ๋Š” ๊ฒฝ์šฐ, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ์ง€์›ํ•˜์ง€ ์•Š์„ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ ์•ฑ์€ ์ตœ์‹  ๋ฒ„์ „๋งŒ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•ด IPA๋ฅผ ์••์ถ• ํ•ด์ œํ•ฉ๋‹ˆ๋‹ค:

unzip redacted.ipa -d unzipped

Info.plist์—์„œ ์ตœ์†Œ ์ง€์› ๋ฒ„์ „์„ ํ™•์ธํ•˜๊ณ , ๊ธฐ๊ธฐ๊ฐ€ ๊ทธ๋ณด๋‹ค ์˜ค๋ž˜๋œ ๊ฒฝ์šฐ ๊ฐ’์„ ๋ณ€๊ฒฝํ•˜์—ฌ ์ง€์›๋˜๋„๋ก ํ•˜์‹ญ์‹œ์˜ค.

IPA๋ฅผ ๋‹ค์‹œ ์••์ถ•ํ•˜์‹ญ์‹œ์˜ค:

cd unzipped
zip -r ../no-min-version.ipa *

๊ทธ๋Ÿฐ ๋‹ค์Œ, ์˜ˆ๋ฅผ ๋“ค์–ด ๋‹ค์Œ๊ณผ ๊ฐ™์ด IPA๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค:

ideviceinstaller -i no-min-version.ipa -w

Cydia์—์„œ AppSync Unified tweak๊ฐ€ ํ•„์š”ํ•  ์ˆ˜ ์žˆ์œผ๋‹ˆ invalid signature ์˜ค๋ฅ˜๋ฅผ ๋ฐฉ์ง€ํ•˜์„ธ์š”.

์„ค์น˜๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด, Cydia์—์„œ Iridium tweak๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•”ํ˜ธํ™” ํ•ด์ œ๋œ IPA๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ถŒํ•œ ํŒจ์น˜ ๋ฐ ์žฌ์„œ๋ช…

get-task-allow ๊ถŒํ•œ์œผ๋กœ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์žฌ์„œ๋ช…ํ•˜๊ธฐ ์œ„ํ•ด app-signer, codesign, iResign๊ณผ ๊ฐ™์€ ์—ฌ๋Ÿฌ ๋„๊ตฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. app-signer๋Š” ์žฌ์„œ๋ช…ํ•  IPA ํŒŒ์ผ์„ ์ง€์ •ํ•˜๊ณ  **get-task-allow**๋ฅผ ์„ค์ •ํ•˜๋ฉฐ ์‚ฌ์šฉํ•  ์ธ์ฆ์„œ์™€ ํ”„๋กœ๋น„์ €๋‹ ํ”„๋กœํ•„์„ ์‰ฝ๊ฒŒ ์ง€์ •ํ•  ์ˆ˜ ์žˆ๋Š” ๋งค์šฐ ์‚ฌ์šฉ์ž ์นœํ™”์ ์ธ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

์ธ์ฆ์„œ ๋ฐ ์„œ๋ช… ํ”„๋กœํ•„์— ๊ด€ํ•ด์„œ๋Š” Apple์ด Xcode๋ฅผ ํ†ตํ•ด ๋ชจ๋“  ๊ณ„์ •์— ๋ฌด๋ฃŒ ๊ฐœ๋ฐœ์ž ์„œ๋ช… ํ”„๋กœํ•„์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์•ฑ์„ ์ƒ์„ฑํ•˜๊ณ  ํ•˜๋‚˜๋ฅผ ๊ตฌ์„ฑํ•˜์„ธ์š”. ๊ทธ๋Ÿฐ ๋‹ค์Œ, Settings โ†’ Privacy & Security๋กœ ์ด๋™ํ•˜์—ฌ ๊ฐœ๋ฐœ์ž ์•ฑ์„ ์‹ ๋ขฐํ•˜๋„๋ก iPhone์„ ๊ตฌ์„ฑํ•˜์„ธ์š”. Developer Mode๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

์žฌ์„œ๋ช…๋œ IPA๋กœ ์ด์ œ ์žฅ์น˜์— ์„ค์น˜ํ•˜์—ฌ ํŽœํ…Œ์ŠคํŠธ๋ฅผ ์ง„ํ–‰ํ•  ์‹œ๊ฐ„์ž…๋‹ˆ๋‹ค:

ideviceinstaller -i resigned.ipa -w

๊ฐœ๋ฐœ์ž ๋ชจ๋“œ ํ™œ์„ฑํ™” (iOS 16+)

iOS 16๋ถ€ํ„ฐ Apple์€ ๊ฐœ๋ฐœ์ž ๋ชจ๋“œ๋ฅผ ๋„์ž…ํ–ˆ์Šต๋‹ˆ๋‹ค: get_task_allow๋ฅผ ํฌํ•จํ•˜๊ฑฐ๋‚˜ ๊ฐœ๋ฐœ ์ธ์ฆ์„œ๋กœ ์„œ๋ช…๋œ ์ด์ง„ ํŒŒ์ผ์€ ์žฅ์น˜์—์„œ ๊ฐœ๋ฐœ์ž ๋ชจ๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋  ๋•Œ๊นŒ์ง€ ์‹คํ–‰์„ ๊ฑฐ๋ถ€ํ•ฉ๋‹ˆ๋‹ค. ์ด ํ”Œ๋ž˜๊ทธ๊ฐ€ ์ผœ์ ธ ์žˆ์ง€ ์•Š์œผ๋ฉด Frida/LLDB๋ฅผ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

  1. ์ž„์˜์˜ ๊ฐœ๋ฐœ์ž ์„œ๋ช… IPA๋ฅผ ์ „ํ™”๊ธฐ์— ์„ค์น˜ํ•˜๊ฑฐ๋‚˜ ํ‘ธ์‹œํ•ฉ๋‹ˆ๋‹ค.
  2. ์„ค์ • โ†’ ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฐ ๋ณด์•ˆ โ†’ ๊ฐœ๋ฐœ์ž ๋ชจ๋“œ๋กœ ์ด๋™ํ•˜์—ฌ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.
  3. ์žฅ์น˜๊ฐ€ ์žฌ๋ถ€ํŒ…๋ฉ๋‹ˆ๋‹ค; ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•œ ํ›„ ๊ฐœ๋ฐœ์ž ๋ชจ๋“œ ์ผœ๊ธฐ๋ฅผ ์š”์ฒญ๋ฐ›์Šต๋‹ˆ๋‹ค.

๊ฐœ๋ฐœ์ž ๋ชจ๋“œ๋Š” ๋น„ํ™œ์„ฑํ™”ํ•˜๊ฑฐ๋‚˜ ์ „ํ™”๊ธฐ๋ฅผ ์ดˆ๊ธฐํ™”ํ•  ๋•Œ๊นŒ์ง€ ํ™œ์„ฑ ์ƒํƒœ๋กœ ์œ ์ง€๋˜๋ฏ€๋กœ ์ด ๋‹จ๊ณ„๋Š” ์žฅ์น˜๋‹น ํ•œ ๋ฒˆ๋งŒ ์ˆ˜ํ–‰ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. Apple ๋ฌธ์„œ์—์„œ ๋ณด์•ˆ ์˜๋ฏธ๋ฅผ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

ํ˜„๋Œ€์ ์ธ ์‚ฌ์ด๋“œ๋กœ๋”ฉ ์˜ต์…˜

์ด์ œ ํƒˆ์˜ฅ ์—†์ด ์‚ฌ์ด๋“œ๋กœ๋”ฉํ•˜๊ณ  ์žฌ์„œ๋ช…๋œ IPA๋ฅผ ์ตœ์‹  ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜๋Š” ๋ช‡ ๊ฐ€์ง€ ์„ฑ์ˆ™ํ•œ ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๋‹ค:

๋„๊ตฌ์š”๊ตฌ ์‚ฌํ•ญ๊ฐ•์ ์ œํ•œ ์‚ฌํ•ญ
AltStore 2 / SideStore๋งค 7์ผ๋งˆ๋‹ค ๋ฌด๋ฃŒ ๊ฐœ๋ฐœ ํ”„๋กœํ•„๋กœ IPA๋ฅผ ์žฌ์„œ๋ช…ํ•˜๋Š” macOS/Windows/Linux ๋™๋ฐ˜์žWi-Fi๋ฅผ ํ†ตํ•œ ์ž๋™ ์žฌ๋กœ๋“œ, iOS 17๊นŒ์ง€ ์ž‘๋™๋™์ผ ๋„คํŠธ์›Œํฌ์— ์žˆ๋Š” ์ปดํ“จํ„ฐ ํ•„์š”, Apple์—์„œ ๋ถ€๊ณผํ•œ 3๊ฐœ ์•ฑ ์ œํ•œ
TrollStore 1/2CoreTrust ๋ฒ„๊ทธ์— ์ทจ์•ฝํ•œ iOS 14 โ€“ 15.4.1 ์žฅ์น˜์˜๊ตฌ ์„œ๋ช… (7์ผ ์ œํ•œ ์—†์Œ); ์„ค์น˜ ํ›„ ์ปดํ“จํ„ฐ ํ•„์š” ์—†์ŒiOS 15.5+์—์„œ ์ง€์›๋˜์ง€ ์•Š์Œ (๋ฒ„๊ทธ ํŒจ์น˜๋จ)

ํ˜„์žฌ iOS ๋ฒ„์ „์—์„œ์˜ ์ •๊ธฐ์ ์ธ ํŽœํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•ด Alt/Side-Store๊ฐ€ ์ผ๋ฐ˜์ ์œผ๋กœ ๊ฐ€์žฅ ์‹ค์šฉ์ ์ธ ์„ ํƒ์ž…๋‹ˆ๋‹ค.

ํ›„ํ‚น / ๋™์  ๊ณ„์ธก

get_task_allow๋กœ ์„œ๋ช…๋˜๊ณ  ๊ฐœ๋ฐœ์ž ๋ชจ๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋˜๋ฉด ํƒˆ์˜ฅ๋œ ์žฅ์น˜์—์„œ์ฒ˜๋Ÿผ ์•ฑ์„ ํ›„ํ‚นํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

# Spawn & attach with objection
objection -g "com.example.target" explore

# Or plain Frida
frida -U -f com.example.target -l my_script.js --no-pause

์ตœ๊ทผ Frida ๋ฆด๋ฆฌ์Šค(>=16)๋Š” ํฌ์ธํ„ฐ ์ธ์ฆ ๋ฐ ๊ธฐํƒ€ iOS 17 ์™„ํ™” ์กฐ์น˜๋ฅผ ์ž๋™์œผ๋กœ ์ฒ˜๋ฆฌํ•˜๋ฏ€๋กœ ๋Œ€๋ถ€๋ถ„์˜ ๊ธฐ์กด ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์ฆ‰์‹œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

ํƒˆ์˜ฅ ์—†์ด MobSF๋ฅผ ์ด์šฉํ•œ ์ž๋™ํ™”๋œ ๋™์  ๋ถ„์„

MobSF๋Š” ์‹ค์ œ ์žฅ์น˜์—์„œ ๋™์ผํ•œ ๊ธฐ์ˆ (get_task_allow)์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐœ๋ฐœ์ž ์„œ๋ช…๋œ IPA๋ฅผ ๊ณ„์ธกํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํŒŒ์ผ ์‹œ์Šคํ…œ ๋ธŒ๋ผ์šฐ์ €, ํŠธ๋ž˜ํ”ฝ ์บก์ฒ˜ ๋ฐ Frida ์ฝ˜์†”์ด ํฌํ•จ๋œ ์›น UI๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹คใ€ใ€‘. ๊ฐ€์žฅ ๋น ๋ฅธ ๋ฐฉ๋ฒ•์€ Docker์—์„œ MobSF๋ฅผ ์‹คํ–‰ํ•œ ๋‹ค์Œ USB๋ฅผ ํ†ตํ•ด iPhone์„ ์—ฐ๊ฒฐํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค:

docker pull opensecurity/mobile-security-framework-mobsf:latest
docker run -p 8000:8000 --privileged \
-v /var/run/usbmuxd:/var/run/usbmuxd \
opensecurity/mobile-security-framework-mobsf:latest
# Browse to http://127.0.0.1:8000 and upload your resigned IPA

MobSF๋Š” ์ด์ง„ ํŒŒ์ผ์„ ์ž๋™์œผ๋กœ ๋ฐฐํฌํ•˜๊ณ , ์•ฑ ์ƒŒ๋“œ๋ฐ•์Šค ๋‚ด์—์„œ Frida ์„œ๋ฒ„๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋ฉฐ, ๋Œ€ํ™”ํ˜• ๋ณด๊ณ ์„œ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

iOS 17 ๋ฐ ์ž ๊ธˆ ๋ชจ๋“œ ์ฃผ์˜์‚ฌํ•ญ

  • ์ž ๊ธˆ ๋ชจ๋“œ (์„ค์ • โ†’ ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฐ ๋ณด์•ˆ)๋Š” ๋™์  ๋ง์ปค๊ฐ€ ์„œ๋ช…๋˜์ง€ ์•Š๊ฑฐ๋‚˜ ์™ธ๋ถ€์—์„œ ์„œ๋ช…๋œ ๋™์  ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ๋กœ๋“œํ•˜๋Š” ๊ฒƒ์„ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค. ์ด ๋ชจ๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋œ ์žฅ์น˜๋ฅผ ํ…Œ์ŠคํŠธํ•  ๋•Œ๋Š” ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•˜๋ฉฐ, ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด Frida/objection ์„ธ์…˜์ด ์ฆ‰์‹œ ์ข…๋ฃŒ๋ฉ๋‹ˆ๋‹ค.
  • ํฌ์ธํ„ฐ ์ธ์ฆ(PAC)์€ A12+ ์žฅ์น˜์—์„œ ์‹œ์Šคํ…œ ์ „๋ฐ˜์— ๊ฑธ์ณ ์‹œํ–‰๋ฉ๋‹ˆ๋‹ค. Frida โ‰ฅ16์€ PAC ์ŠคํŠธ๋ฆฌํ•‘์„ ํˆฌ๋ช…ํ•˜๊ฒŒ ์ฒ˜๋ฆฌํ•˜๋ฏ€๋กœ, ์ƒˆ๋กœ์šด ์ฃผ์š” iOS ๋ฒ„์ „์ด ์ถœ์‹œ๋  ๋•Œ frida-server์™€ Python/CLI ํˆด์ฒด์ธ์„ ๋ชจ๋‘ ์ตœ์‹  ์ƒํƒœ๋กœ ์œ ์ง€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ ๋ฌธํ—Œ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ