
iOS-Plattformsicherheit & Anti-Tampering Swift-Bibliothek
Schauen Sie sich unseren praktischen & komplett online Kurs an unter: https://courses.securing.pl/courses/iase


🌏 iOS Security Suite ist eine fortschrittliche und benutzerfreundliche Plattform-Sicherheits- und Anti-Manipulations-Bibliothek, die in reinem Swift geschrieben ist! Wenn Sie für iOS entwickeln und Ihre App gemäß dem OWASP MASVS Standard, Kapitel v8, schützen möchten, dann könnte diese Bibliothek Ihnen viel Zeit sparen. 🚀
Was ISS erkennt:
Es gibt 4 Möglichkeiten, IOSSecuritySuite zu verwenden
Fügen Sie die Dateien IOSSecuritySuite/*.swift zu Ihrem Projekt hinzu
pod 'IOSSecuritySuite'
github "securing/IOSSecuritySuite"
.package(url: "https://github.com/securing/IOSSecuritySuite.git", from: "1.5.0")
Nachdem Sie ISS zu Ihrem Projekt hinzugefügt haben, müssen Sie auch Ihre Haupt-Info.plist aktualisieren. Es gibt eine Prüfung im Jailbreak-Erkennungsmodul, die die Methode canOpenURL(_:) verwendet und erfordert, dass die URLs angegeben werden, die abgefragt werden.
<key>LSApplicationQueriesSchemes</key>
<array>
<string>undecimus</string>
<string>sileo</string>
<string>zbra</string>
<string>filza</string>
</array>
Überprüfen Sie unsere EULA-Lizenz für die Details.
TLDR: Wenn Ihr Unternehmen beschäftigt:
Wenn Sie ein Modul verkaufen möchten, das die iOS Security Suite verwendet (es wird nicht direkt in Ihrer App verwendet) - 10.000 EUR/Jahr
iOS Security Suite ist für die Verwendung auf iOS/iPadOS vorgesehen. Es sollte nicht auf Macs mit Apple Silicon verwendet werden.
if IOSSecuritySuite.amIJailbroken() {
print("This device is jailbroken")
} else {
print("This device is not jailbroken")
}
let jailbreakStatus = IOSSecuritySuite.amIJailbrokenWithFailMessage()
if jailbreakStatus.jailbroken {
print("This device is jailbroken")
print("Because: \(jailbreakStatus.failMessage)")
} else {
print("This device is not jailbroken")
}
Die failMessage ist ein String, der durch Kommas getrennte Indikatoren enthält, wie im folgenden Beispiel gezeigt:
sileo:// URL-Schema erkannt, Verdächtige Datei existiert: /Library/MobileSubstrate/MobileSubstrate.dylib, Fork konnte einen neuen Prozess erstellen
let jailbreakStatus = IOSSecuritySuite.amIJailbrokenWithFailedChecks()
if jailbreakStatus.jailbroken {
if (jailbreakStatus.failedChecks.contains { $0.check == .existenceOfSuspiciousFiles }) && (jailbreakStatus.failedChecks.contains { $0.check == .suspiciousFilesCanBeOpened }) {
print("This is real jailbroken device")
}
}
let amIDebugged: Bool = IOSSecuritySuite.amIDebugged()
IOSSecuritySuite.denyDebugger()
let runInEmulator: Bool = IOSSecuritySuite.amIRunInEmulator()
if IOSSecuritySuite.amIReverseEngineered() {
print("This device has evidence of reverse engineering")
} else {
print("This device hasn't evidence of reverse engineering")
}
let reverseStatus = IOSSecuritySuite.amIReverseEngineeredWithFailedChecks()
if reverseStatus.reverseEngineered {
// check for reverseStatus.failedChecks for more details
}
Jetzt können Sie auch erkennen, ob eine App mit einem VPN verbunden ist
let amIProxied: Bool = IOSSecuritySuite.amIProxied(considerVPNConnectionAsProxy: true)
let amIInLockdownMode: Bool = IOSSecuritySuite.amIInLockdownMode()
let amIRuntimeHooked: Bool = amIRuntimeHook(dyldWhiteList: dylds, detectionClass: SomeClass.self, selector: #selector(SomeClass.someFunction), isClassMethod: false)
// If we want to deny symbol hook of Swift function, we have to pass mangled name of that function
denySymbolHook("$s10Foundation5NSLogyySS_s7CVarArg_pdtF") // denying hooking for the NSLog function
NSLog("Hello Symbol Hook")
denySymbolHook("abort")
abort()
// Function declaration
func someFunction(takes: Int) -> Bool {
return false
}
// Defining FunctionType : @convention(thin) indicates a “thin” function reference, which uses the Swift calling convention with no special “self” or “context” parameters.
typealias FunctionType = @convention(thin) (Int) -> (Bool)
// Getting pointer address of function we want to verify
func getSwiftFunctionAddr(_ function: @escaping FunctionType) -> UnsafeMutableRawPointer {
return unsafeBitCast(function, to: UnsafeMutableRawPointer.self)
}
let funcAddr = getSwiftFunctionAddr(someFunction)
let amIMSHooked = IOSSecuritySuite.amIMSHooked(funcAddr)
// Function declaration
func denyDebugger(value: Int) {
}
// Defining FunctionType : @convention(thin) indicates a “thin” function reference, which uses the Swift calling convention with no special “self” or “context” parameters.
typealias FunctionType = @convention(thin) (Int)->()
// Getting original function address
let funcDenyDebugger: FunctionType = denyDebugger
let funcAddr = unsafeBitCast(funcDenyDebugger, to: UnsafeMutableRawPointer.self)
if let originalDenyDebugger = denyMSHook(funcAddr) {
// Call the original function with 1337 as Int argument
unsafeBitCast(originalDenyDebugger, to: FunctionType.self)(1337)
} else {
denyDebugger()
}
// Determine if application has been tampered with
if IOSSecuritySuite.amITampered([.bundleID("biz.securing.FrameworkClientApp"),
.mobileProvision("2976c70b56e9ae1e2c8e8b231bf6b0cff12bbbd0a593f21846d9a004dd181be3"),
.machO("IOSSecuritySuite", "6d8d460b9a4ee6c0f378e30f137cebaf2ce12bf31a2eef3729c36889158aa7fc")]).result {
print("I have been Tampered.")
}
else {
print("I have not been Tampered.")
}