Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
iblessing — iblessing es un kit de herramientas de explotación de seguridad para iOS, que incluye principalmente recopilación de información de aplicaciones, análisis estático y análisis dinámico. Puede utilizarse para ingeniería inversa, análisis binario y minería de vulnerabilidades. | Kitploit
Herramientas/GitHubGitHub/soulghost/iblessing
Análisis EstáticoAnálisis Dinámico (Sandboxing)Seguridad iOSAnálisis de VulnerabilidadesExplotaciónIngeniería InversaSeguridad MóvilAnálisis de BinariosTop en Seguridad iOS #10
684958hace 4 añosRevisado por Kitploit
GitHub
soulghost/iblessing

iblessing

iblessing es un kit de herramientas de explotación de seguridad para iOS, que incluye principalmente recopilación de información de aplicaciones, análisis estático y análisis dinámico. Puede utilizarse para ingeniería inversa, análisis binario y minería de vulnerabilidades.

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

☠️ ██╗██████╗ ██╗ ███████╗███████╗███████╗██╗███╗ ██╗ ██████╗ ██║██╔══██╗██║ ██╔════╝██╔════╝██╔════╝██║████╗ ██║██╔════╝ ██║██████╔╝██║ █████╗ ███████╗███████╗██║██╔██╗ ██║██║ ███╗ ██║██╔══██╗██║ ██╔══╝ ╚════██║╚════██║██║██║╚██╗██║██║ ██║ ██║██████╔╝███████╗███████╗███████║███████║██║██║ ╚████║╚██████╔╝ ╚═╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝╚═╝╚═╝ ╚═══╝ ╚═════╝

Build Status Releases

iblessing

  • iblessing es un conjunto de herramientas de explotación de seguridad para iOS, que incluye principalmente recopilación de información de aplicaciones, análisis estático y análisis dinámico.
  • iblessing se basa en unicorn engine, capstone engine y keystone engine.

Características

  • 🔥 Multiplataforma: Probado en macOS y Ubuntu.

  • Extracción de información estática de aplicaciones iOS, incluyendo metadatos, deeplinks, urls, etc.

  • Analizador Mach-O y simulador de enlace de símbolos dyld

  • Realización y análisis de clases Objective-C

  • Escáneres que realizan análisis dinámico para código ensamblador arm64 y encuentran información clave o superficie de ataque

  • Escáneres que utilizan unicorn para simular parcialmente la ejecución de código Mach-O arm64 y encontrar algunas características

  • Generadores que pueden proporcionar procesamiento secundario en el informe del escáner para iniciar un servidor de consultas, o generar script para IDA

  • Escáner súper objc_msgSend xrefs 😄

    • Emulación de métodos objc y subs (como bloques) para generar xrefs como flare-emu
    • Detección de envoltorios de funciones objc y generación de ida usercall
    • Análisis de subfunciones objc_msgSend
    • xrefs objc block a objc_msgSend en argumentos y lista de captura
    • Formato de informe incluyendo json, etc.
    • Análisis de clases y métodos Swift
    • Seguimiento de ramas y llamadas
    • SimProcedures para símbolos externos
  • Pruebas

  • Soporte de Escáneres Android

  • Registros de diagnóstico

  • Infraestructura de escáner más flexible para nuevos plugins de escáner

  • Soporte

    En caso de que necesites soporte sobre iblessing o cualquier cosa asociada, puedes:

    • crear un issue y proporcionar la información necesaria
    • contactar a Sou1gh0st en Twitter
    • enviar correo a xiuyutong1994#163.com
    • enviar correo a xiuyutong1994#gmail.com

    Registro de cambios

    • 2021.06.27 - Nueva arquitectura (Programa Shell + Biblioteca Principal) y soporte de plugins (beta)
    • 2021.01.23 - Añadidas firmas de métodos para bibliotecas del sistema (Foundation, UIKit), capacidades analíticas mejoradas (https://github.com/Soulghost/iblessing/wiki/System-Libraries-(Foundation,-UIKit)-Simple-SimProcedure)
    • 2020.11.30 - Información de reflexión Objc (https://github.com/Soulghost/iblessing/wiki/Objc-Reflection-Info)
    • 2020.10.24 - Instantáneas de llamadas Objc (https://github.com/Soulghost/iblessing/wiki/Objc-Call-Snapshots)
    • 2020.10.04 - Soporte de lista de categorías Objc
    • 2020.09.28 - Soporte de bibliotecas estáticas y fat mach-o
    • 2020.09.22 - Estado básico del programa y bifurcación condicional
    • 2020.09.04 - Validación de métodos, inferencia, soporte de objc_msgSendSuper
    • 2020.08.11 - Ahora iblessing es una herramienta multiplataforma, compatible con macOS y Linux 😆
    • 2020.08.08 - Mejora del escáner de xrefs objc_msgSend, añadido soporte de sub xrefs, incluyendo argumentos de bloque y lista de captura
    • 2020.07.30 - Mejora del escáner symbol-wrapper, y añadidos scripts de IDA para renombrar envoltorios de símbolos y modificación de prototipos
    • 2020.07.21 - Primera versión

    Primeros pasos

    ⚠️⚠️⚠️ Los escáneres binarios requieren 12 GB de espacio de memoria virtual para cargar un archivo mach-o, pero no consumirán tanto. Por lo tanto, debes asegurarte de que la memoria física de tu máquina de trabajo sea superior a 12 GB, o de que la memoria virtual asignable sea mayor a 12 GB a través del mecanismo de archivo de intercambio.

    1. Puedes descargar el binario prepublicado de iblessing y disfrutarlo.
    2. Ejecuta chmod +x para el binario.
    3. Para más tutoriales, consulta la Documentación y Ayuda a continuación.

    Cómo usar

    • Versiones https://github.com/Soulghost/iblessing/releases

    Binario Todo en Uno

    • iblessing-darwin-all/iblessing-linux

    Programa Shell + Dylib

    • descomprimir iblessing-framework.tar.gz
    • iblessing-darwin/iblessing-linux + libiblessing-core.dylib/libiblessing-core.so

    Desarrolla tus propias herramientas basadas en iblessing Framework

    • descomprimir iblessing-framework.tar.gz
    • tu binario + libiblessing-core.dylib/libiblessing-core.so + include/iblessing-core
    • código de ejemplo: iblessing-core/otool.cpp

    Cómo compilar

    CMake

    • Plataforma: macOS, Linux

    Para comenzar a compilar iblessing, sigue los pasos a continuación:``` git clone --recursive -j4 https://github.com/Soulghost/iblessing cd iblessing ./compile-cmake.sh

    root@kitploit:~
    ## Atajos
    - [Conceptos Básicos](https://github.com/Soulghost/iblessing#basic-concepts)
    - Escáneres
      - [Escanear AppInfos](https://github.com/Soulghost/iblessing#scan-for-appinfos) ⚠️ No disponible actualmente en Linux
      - [Escanear XREFs de Clase](https://github.com/Soulghost/iblessing#scan-for-class-xrefs)
      - [Escanear todos los XREFs de objc_msgSend](https://github.com/Soulghost/iblessing#scan-for-all-objc_msgsend-xrefs)
      - [Escanear Wrappers de Símbolos Simples](https://github.com/Soulghost/iblessing/blob/features/anti_wrapper/README.md#scan-for-symbol-wrappers)
     
    - Generadores
      - [Generar Servidor de Consulta de Xrefs de objc_msgSend](https://github.com/Soulghost/iblessing#generate-objc_msgsend-xrefs-query-server)
      - [Generar Scripts de IDA para xrefs de objc_msgSend](https://github.com/Soulghost/iblessing#generate-ida-scripts-for-objc_msgsend-xrefs)
      - [Generar Scripts de IDA para renombrar wrappers de funciones objc y modificación de prototipos](https://github.com/Soulghost/iblessing/blob/features/anti_wrapper/README.md#genereate-ida-script-for-objc-runtime-function-rename-and-prototype-modification)
    
    ***Si hay algún error, puedes compilar manualmente capstone y unicorn, luego arrastra libcapstone.a y libunicorn.a a vendor/libs del proyecto Xcode.***
    
    Si todo esto se ejecuta correctamente, puedes encontrar el binario en el directorio build:```
    > ls ./build
    iblessing
    
    > file ./build/iblessing
    ./build/iblessing: Mach-O 64-bit executable x86_64
    

    Documentación y Ayuda

    Vista previa```

    $ iblessing -h

    root@kitploit:~
           ☠️
           ██╗██████╗ ██╗     ███████╗███████╗███████╗██╗███╗   ██╗ ██████╗
           ██║██╔══██╗██║     ██╔════╝██╔════╝██╔════╝██║████╗  ██║██╔════╝
           ██║██████╔╝██║     █████╗  ███████╗███████╗██║██╔██╗ ██║██║  ███╗
           ██║██╔══██╗██║     ██╔══╝  ╚════██║╚════██║██║██║╚██╗██║██║   ██║
           ██║██████╔╝███████╗███████╗███████║███████║██║██║ ╚████║╚██████╔╝
           ╚═╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝╚═╝╚═╝  ╚═══╝ ╚═════╝
    

    [] iblessing iOS Security Exploiting Toolkit Beta 0.1.1 (http://blog.asm.im) [] Author: Soulghost (高级页面仔) @ (https://github.com/Soulghost)

    Usage: iblessing [options...] Options: -m, --mode mode selection: * scan: use scanner * generator: use generator -i, --identifier choose module by identifier: * : use specific scanner * : use specific generator -f, --file input file path -o, --output output file path -l, --list list available scanners -d, --data extra data -h, --help Shows this page

    root@kitploit:~
    ## Conceptos Básicos
    ### Escáner
    Un escáner es un componente utilizado para generar un informe de análisis mediante el análisis estático y dinámico de archivos binarios; por ejemplo, el escáner objc-msg-xref puede analizar dinámicamente la mayoría de las referencias cruzadas de objc_msgSend.```
    [*] Scanner List:
        - app-info: extract app infos
        - objc-class-xref: scan for class xrefs
        - objc-msg-xref: generate objc_msgSend xrefs record
        - predicate: scan for NSPredicate xrefs and sql injection surfaces
        - symbol-wrapper: detect symbol wrappers
    

    Generator

    Un generador es un componente que realiza un procesamiento secundario sobre el informe generado por el escáner, por ejemplo, puede generar scripts de IDA basados en el el informe de referencias cruzadas del escáner objc-msg-xref.``` [*] Generator List: - ida-objc-msg-xref: generator ida scripts to add objc_msgSend xrefs from objc-msg-xref scanner's report - objc-msg-xref-server: server to query objc-msg xrefs - objc-msg-xref-statistic: statistics among objc-msg-send reports

    root@kitploit:~
    ## Uso Básico
    ### Escanear en busca de AppInfos
    ⚠️ **Debido a que parte de la dependencia de Cocoa no se ha eliminado (como el analizador bplist), actualmente no está disponible en Linux.**```
    > iblessing -m scan -i app-info -f <path-to-app-bundle>
    

    Tomemos WeChat como ejemplo:```

    iblessing -m scan -i app-info -f WeChat.app [] set output path to /opt/one-btn/tmp/apps/WeChat/Payload [] input file is WeChat.app [] start App Info Scanner [+] find default plist file Info.plist! [] find version info: Name: 微信(WeChat) Version: 7.0.14(18E226) ExecutableName: WeChat [] Bundle Identifier: com.tencent.xin [] the app allows HTTP requests without exception domains! [+] find app deeplinks |-- wechat:// |-- weixin:// |-- fb290293790992170:// |-- weixinapp:// |-- prefs:// |-- wexinVideoAPI:// |-- QQ41C152CF:// |-- wx703:// |-- weixinULAPI:// [] find app callout whitelist |-- qqnews:// |-- weixinbeta:// |-- qqnewshd:// |-- qqmail:// |-- whatsapp:// |-- wxwork:// |-- wxworklocal:// |-- wxcphonebook:// |-- mttbrowser:// |-- mqqapi:// |-- mqzonev2:// |-- qqmusic:// |-- tenvideo2:// ... [+] find 507403 string literals in binary [] process with string literals, this maybe take some time [+] find self deeplinks URLs: |-- weixin://opennativeurl/devicerankview |-- weixin://dl/offlinepay/?appid=%@ |-- weixin://opennativeurl/rankmyhomepage ... [+] find other deeplinks URLs: |-- wxpay://f2f/f2fdetail |-- file://%@?lang=%@&fontRatio=%.2f&scene=%u&version=%u&type=%llu&%@=%d&qqFaceFolderPath=%@&platform=iOS&netType=%@&query=%@&searchId=%@&isHomePage=%d&isWeAppMore=%d&subType=%u&extParams=%@&%@=%@&%@=%@ ... [*] write report to path /opt/one-btn/tmp/apps/WeChat/Payload/WeChat.app_info.iblessing.txt

    ls -alh -rw-r--r--@ 1 soulghost wheel 29K Jul 23 14:01 WeChat.app_info.iblessing.txt

    root@kitploit:~
    ### Escaneo de XREFs de Clase
    ***Aviso: Solo binarios ARM64***```
    iblessing -m scan -i objc-class-xref -f <path-to-binary> -d 'classes=<classname_to_scan>,<classname_to_scan>,...'
    

    Problemas Conocidos```

    restore-symbol WeChat -o WeChat.restored iblessing -m scan -i objc-class-xref -f WeChat.restored -d 'classes=NSPredicate' [] set output path to /opt/one-btn/tmp/apps/WeChat/Payload [] input file is WeChat [+] detect mach-o header 64 [+] detect litten-endian [] start Objc Class Xref Scanner [] try to find OBJC_CLASS$_NSPredicate [] Step 1. locate class refs [+] find OBJC_CLASS$_NSPredicate at 0x108eb81d8 [] Step 2. find __TEXT,__text [+] find __TEXT,__text at 0x4000 [] Step 3. scan in __text [] start disassembler at 0x100004000 [] \ 0x1002e1a50/0x1069d9874 (2.71%) [+] find OBJC_CLASS$_NSPredicate ref at 0x1002e1a54 ... [] Step 4. symbolicate ref addresses [+] OBJC_CLASS$_NSPredicate -| [+] find OBJC_CLASS$_NSPredicate ref -[WCWatchNotificationMgr addYoCount:contact:type:] at 0x1002e1a54 [+] find OBJC_CLASS$_NSPredicate ref -[NotificationActionsMgr handleSendMsgResp:] at 0x1003e0e28 [+] find OBJC_CLASS$_NSPredicate ref -[FLEXClassesTableViewController searchBar:textDidChange:] at 0x1004a090c [+] find OBJC_CLASS$_NSPredicate ref +[GameCenterUtil parameterValueForKey:fromQueryItems:] at 0x1005a823c [+] find OBJC_CLASS$_NSPredicate ref +[GameCenterUtil getNavigationBarColorForUrl:defaultColor:] at 0x1005a8cd8 ...

    root@kitploit:~
    ### Escanear todas las XREFs de objc_msgSend
    ***Aviso: Solo binarios ARM64***
    
    #### Modo Simple```
    iblessing -m scan -i objc-msg-xref -f <path-to-binary>
    

    Modo Anti-Wrapper```

    iblessing -m scan -i objc-msg-xref -f WeChat -d 'antiWrapper=1'

    root@kitploit:~
    El modo anti-wrapper detectará envoltorios de objc_msgSend y realizará transformaciones, tales como:```arm
    ; __int64 __usercall objc_msgSend_X0_X22_X20@<X0>(void *obj@<X0>, const char *sel@<X22>, id anyObj@<X20>, ...)
    objc_msgSend_X0_X22_X20:
    MOV             X1, X22
    MOV             X2, X20
    B               objc_msgSend
    

    Ejemplo de uso:```

    iblessing -m scan -i objc-msg-xref -f WeChat -d 'antiWrapper=1' [] set output path to /opt/one-btn/tmp/apps/WeChat/Payload [] input file is WeChat [+] detect mach-o header 64 [+] detect litten-endian

    [] !!! Notice: enter anti-wrapper mode, start anti-wrapper scanner [] start Symbol Wrapper Scanner [] try to find wrappers for_objc_msgSend [] Step1. find __TEXT,__text [+] find __TEXT,__text at 0x100004000 [+] mapping text segment 0x100000000 ~ 0x107cb0000 to unicorn engine [] Step 2. scan in __text [] start disassembler at 0x100004000 [] / 0x1069d986c/0x1069d9874 (100.00%) [] reach to end of __text, stop [+] anti-wrapper finished

    [] start ObjcMethodXrefScanner Exploit Scanner [] Step 1. realize all app classes [] realize classes 14631/14631 (100.00%) [+] get 667318 methods to analyze [] Step 2. dyld load non-lazy symbols [] Step 3. track all calls [] progress: 667318 / 667318 (100.00%) [] Step 4. serialize call chains to file [] saved to /opt/one-btn/tmp/apps/WeChat/Payload/WeChat_method-xrefs.iblessing.txt

    ls -alh WeChat_method-xrefs.iblessing.txt -rw-r--r-- 1 soulghost wheel 63M Jul 23 14:46 WeChat_method-xrefs.iblessing.txt

    head WeChat_method-xrefs.iblessing.txt iblessing methodchains,ver:0.2; chainId,sel,prefix,className,methodName,prevMethods,nextMethods 182360,0x1008a0ab8,+[A8KeyControl initialize],+,A8KeyControl,initialize,[],[4429#0x1008a1064@4376#0x1008a1050@13769#0x1008a10d0] 182343,0x1008a0ad0,+[A8KeyControl_QueryStringTransferCookie initialize],+,A8KeyControl_QueryStringTransferCookie,initialize,[],[4429#0x1008a1064@4376#0x1008a1050@13769#0x1008a10d0] 145393,0x1008c2220,+[A8KeyResultCookieWriter initWithDomain:weakWebView:andCompleteBlock:],+,A8KeyResultCookieWriter,initWithDomain:weakWebView:andCompleteBlock:,[145386#0x10036367c],[] 145396,0x1008c3df8,+[A8KeyResultCookieWriter setA8KeyCookieExpireTime:],+,A8KeyResultCookieWriter,setA8KeyCookieExpireTime:,[145386#0x1003636e8],[] 145397,0x1008c27e8,+[A8KeyResultCookieWriter writeCompleteMarkerCookieValue:forKey:],+,A8KeyResultCookieWriter,writeCompleteMarkerCookieValue:forKey:,[145386#0x10036380c],[] 253456,0x0,+[AAOperationReq init],+,AAOperationReq,init,[253455#0x1039a9d30],[] 253457,0x0,+[AAOperationReq setBaseRequest:],+,AAOperationReq,setBaseRequest:,[253455#0x1039a9d8c],[] 186847,0x0,+[AAOperationRes length],+,AAOperationRes,length,[186845#0x10342aa54],[]

    root@kitploit:~
    El informe puede ser utilizado por los generadores, ahora vamos.
    
    ### Generar servidor de consultas de objc_msgSend Xrefs
    Puede iniciar un servidor a través del generador objc-msg-xref-server de iblessing para consultar todas las referencias cruzadas de objc_msgSend.```
    iblessing -m generator -i objc-msg-xref-server -f <path-to-report-generated-by-objc-msg-xref-scanner>
    

    Especificar el host y puerto de escucha

    La dirección de escucha predeterminada es 127.0.0.1:2345, puedes especificarla con la opción -d.``` iblessing -m generator -i objc-msg-xref-server -f WeChat_method-xrefs.iblessing.txt -d 'host=0.0.0.0;port=12345'

    root@kitploit:~
    #### Ejemplo de Uso
    ***Aviso: objc-msg-xref está basado en unicorn, para acelerar el análisis, no seguimos ninguna llamada, por lo que el resultado está parcialmente incompleto.***```
    > iblessing -m generator -i objc-msg-xref-server -f WeChat_method-xrefs.iblessing.txt
    [*] set output path to /opt/one-btn/tmp/apps/WeChat/Payload
    [*] input file is WeChat_method-xrefs.iblessing.txt
    [*] start ObjcMsgXREFServerGenerator
      [*] load method-chain db for version iblessing methodchains,ver:0.2;
      [*] table keys chainId,sel,prefix,className,methodName,prevMethods,nextMethods
    	[-] bad line 104467,0x0,+[TPLock P,	],+,TPLock,P,	,[104426#0x1043b9904],[]
    	[-] bad line 114905,0x0,?[0x108ce1578 (,],?,0x108ce1578,(,,[114900#0x1011e8c68],[]
    	[-] bad line 104464,0x0,?[? P,	],?,?,P,	,[104426#0x1043b98a8],[]
    	[-] bad line 139234,0x0,?[? X
    	[-] bad line ],?,?,X
    	[-] bad line ,[139205#0x1013c222c],[]
    	[+] load storage from disk succeeded!
      [*] listening on http://127.0.0.1:2345
    

    A continuación, puedes abrir http://127.0.0.1:2345 con un navegador para consultar las referencias cruzadas de objc_msgSend que desees:

    Generar scripts de IDA para referencias cruzadas de objc_msgSend

    Puedes añadir las referencias cruzadas de objc_msgSend generadas por el escáner objc-msg-xref para hacer tu viaje de ingeniería inversa más rápido y cómodo.``` iblessing -m generator -i ida-objc-msg-xref -f

    root@kitploit:~
    #### Ejemplo de uso
    ***Aviso: objc-msg-xref se basa en unicorn; para acelerar el análisis, no seguimos ninguna llamada, por lo que el resultado está parcialmente incompleto.***```
    > iblessing -m generator -i ida-objc-msg-xref -f WeChat_method-xrefs.iblessing.txt
    [*] set output path to /opt/one-btn/tmp/apps/WeChat/Payload
    [*] input file is WeChat_method-xrefs.iblessing.txt
    [*] start IDAObjMsgXREFGenerator
      [*] load method-chain db for version iblessing methodchains,ver:0.2;
      [*] table keys chainId,sel,prefix,className,methodName,prevMethods,nextMethods
    	[-] bad line 104467,0x0,+[TPLock P,	],+,TPLock,P,	,[104426#0x1043b9904],[]
    	[-] bad line 114905,0x0,?[0x108ce1578 (,],?,0x108ce1578,(,,[114900#0x1011e8c68],[]
    	[-] bad line 104464,0x0,?[? P,	],?,?,P,	,[104426#0x1043b98a8],[]
    	[-] bad line 139234,0x0,?[? X
    	[-] bad line ],?,?,X
    	[-] bad line ,[139205#0x1013c222c],[]
    	 [+] load storage from disk succeeded!
      [*] Generating XREF Scripts ...
      [*] saved to /opt/one-btn/tmp/apps/WeChat/Payload/WeChat_method-xrefs.iblessing.txt_ida_objc_msg_xrefs.iblessing.py
      
    > ls -alh WeChat_method-xrefs.iblessing.txt_ida_objc_msg_xrefs.iblessing.py
    -rw-r--r--  1 soulghost  wheel    23M Jul 23 16:16 WeChat_method-xrefs.iblessing.txt_ida_objc_msg_xrefs.iblessing.py
    
    > head WeChat_method-xrefs.iblessing.txt_ida_objc_msg_xrefs.iblessing.py
    def add_objc_xrefs():
        ida_xref.add_cref(0x10036367c, 0x1008c2220, XREF_USER)
        ida_xref.add_cref(0x1003636e8, 0x1008c3df8, XREF_USER)
        ida_xref.add_cref(0x10036380c, 0x1008c27e8, XREF_USER)
        ida_xref.add_cref(0x103add16c, 0x700006e187a8, XREF_USER)
        ida_xref.add_cref(0x102cbee0c, 0x101143ee8, XREF_USER)
        ida_xref.add_cref(0x10085c92c, 0x1005e9360, XREF_USER)
        ida_xref.add_cref(0x10085c8bc, 0x1005e9274, XREF_USER)
        ida_xref.add_cref(0x10085c8dc, 0x1005e92bc, XREF_USER)
        ida_xref.add_cref(0x10085c8cc, 0x1005e9298, XREF_USER)
    

    A continuación, abre IDA -> Archivo -> Script File y carga el script; este paso puede llevar mucho tiempo. Cuando termine, encontrarás muchas referencias cruzadas (xrefs) para el método objc:

    Escanear wrappers de símbolos

    Un archivo Mach-O puede contener múltiples wrappers de símbolos importados de bibliotecas dinámicas de uso común, como:```arm __text:00000001003842D8 sub_1003842CC ; CODE XREF: -[BDARVLynxTracker eventV3:params:adExtraData:]+168↑p __text:00000001003842D8 ; -[BDARVLynxTracker eventV3:params:adExtraData:]+214↑p ... __text:00000001003842D8 MOV X1, X27 __text:00000001003842DC MOV X2, X19 __text:00000001003842E0 B objc_msgSend

    root@kitploit:~
    Podemos convertir el wrapper mediante usercall:```arm
    __text:00000001003842CC ; id __usercall objc_msgSend_61@<X0>(id@<X23>, const char *@<X28>, ...)
    __text:00000001003842CC _objc_msgSend_61                        ; CODE XREF: -[BDARVLynxTracker eventV3:params:adExtraData:]+2CC↑p
    __text:00000001003842CC                                         ; -[BDARVLynxTracker eventV3:params:adExtraData:]+320↑p ...
    __text:00000001003842CC                 MOV             X0, X23
    __text:00000001003842D0                 MOV             X1, X28
    __text:00000001003842D4                 B               objc_msgSend
    

    El escáner puede generar un informe para registrar todos los wrappers, luego puedes usar el generador ida-symbol-wrapper-naming para generar scripts de ida e implementar el cambio de nombre y prototipo de este wrapper.

    Cómo Usar```

    iblessing -m scan -i symbol-wrapper -f -d 'symbols=_objc_msgSend,_objc_retain,_objc_release' iblessing -m scan -i symbol-wrapper -f -d 'symbols=*'

    root@kitploit:~
    #### Ejemplo de uso
    Tomaremos TikTok China como ejemplo:```
    > iblessing -m scan -i symbol-wrapper -f /opt/one-btn/tmp/apps/抖音短视频/Payload/Aweme -d 'symbols=*'
    [*] set output path to /Users/soulghost/Desktop/git/iblessing-public/iblessing/build/Debug
    [*] input file is /opt/one-btn/tmp/apps/抖音短视频/Payload/Aweme
    [+] detect mach-o header 64
    [+] detect litten-endian
    [*] start Symbol Wrapper Scanner
      [*] try to find wrappers for_objc_autoreleaseReturnValue, _objc_msgSend, _objc_release, _objc_releaseAndReturn, _objc_retain, _objc_retainAutorelease, _objc_retainAutoreleaseAndReturn, _objc_retainAutoreleaseReturnValue, _objc_retainAutoreleasedReturnValue
      [*] Step1. find __TEXT,__text
    	[+] find __TEXT,__text at 0x100004000
    	[+] mapping text segment 0x100000000 ~ 0x106da0000 to unicorn engine
      [*] Step 2. scan in __text
    	[*] start disassembler at 0x100004000
    	[*] / 0x106b68a54/0x106b68a58 (100.00%)
    	[*] reach to end of __text, stop
    
      [*] Step 3. serialize wrapper graph to file
    	[*] saved to /Users/soulghost/Desktop/git/iblessing-public/iblessing/build/Debug/Aweme_wrapper-graph.iblessing.txt
    
    > head Aweme_wrapper-graph.iblessing.txt
    iblessing symbol-wrappers,ver:0.1;
    wrapperId;address;name;prototype
    0;0x100022190;_objc_retainAutoreleasedReturnValue;id __usercall f@<x0>(id@<x0>)
    1;0x100022198;_objc_retainAutoreleasedReturnValue;id __usercall f@<x0>(id@<x0>)
    2;0x1000221a0;_objc_release;id __usercall f@<x0>(id@<x22>)
    3;0x1000221a8;_objc_msgSend;id __usercall f@<x0>(id@<x0>, const char*@<x20>, ...)
    4;0x100022448;_objc_release;id __usercall f@<x0>(id@<x21>)
    5;0x10009c19c;_objc_autoreleaseReturnValue;id __usercall f@<x0>(id@<x0>)
    6;0x1000b6f94;_objc_msgSend;id __usercall f@<x0>(id@<x0>, const char*@<x1>, ...)
    7;0x100100248;_objc_autoreleaseReturnValue;id __usercall f@<x0>(id@<x0>)
    

    A continuación, podemos generar ida scripts a partir de este informe.

    Genereate IDA Script for Objc Runtime Function Rename and Prototype Modification```

    iblessing -m generator -i ida-symbol-wrapper-naming -f

    root@kitploit:~
    #### Ejemplo de uso```
    > iblessing -m generator -i ida-symbol-wrapper-naming -f Aweme_wrapper-graph.iblessing.txt
    [*] set output path to /Users/soulghost/Desktop/git/iblessing-public/iblessing/build/Debug
    [*] input file is Aweme_wrapper-graph.iblessing.txt
    [*] start IDAObjMsgXREFGenerator
      [*] load symbol-wrappers db for version iblessing symbol-wrappers,ver:0.1;
      [*] table keys wrapperId;address;name;prototype
      [*] Generating Naming Scripts ...
      [*] saved to /Users/soulghost/Desktop/git/iblessing-public/iblessing/build/Debug/Aweme_wrapper-graph.iblessing.txt_ida_symbol_wrapper_naming.iblessing.py
      
    > head Aweme_wrapper-graph.iblessing.txt_ida_symbol_wrapper_naming.iblessing.py
    def namingWrappers():
        idc.set_name(0x100022190, '_objc_retainAutoreleasedReturnValue', ida_name.SN_FORCE)
        idc.apply_type(0x100022190, idc.parse_decl('id __usercall f@<x0>(id@<x0>)', idc.PT_SILENT))
        idc.set_name(0x100022198, '_objc_retainAutoreleasedReturnValue', ida_name.SN_FORCE)
        idc.apply_type(0x100022198, idc.parse_decl('id __usercall f@<x0>(id@<x0>)', idc.PT_SILENT))
        idc.set_name(0x1000221a0, '_objc_release', ida_name.SN_FORCE)
        idc.apply_type(0x1000221a0, idc.parse_decl('id __usercall f@<x0>(id@<x22>)', idc.PT_SILENT))
        idc.set_name(0x1000221a8, '_objc_msgSend', ida_name.SN_FORCE)
        idc.apply_type(0x1000221a8, idc.parse_decl('id __usercall f@<x0>(id@<x0>, const char*@<x20>, ...)', idc.PT_SILENT))
        idc.set_name(0x100022448, '_objc_release', ida_name.SN_FORCE)
    

    A continuación, abre tu IDA -> File -> Script File y carga el script; este paso puede llevar mucho tiempo. Y cuando termine, podrás observar algunos cambios en el código descompilado:

    ⬇️ ⬇️ ⬇️

    Continuará

    Descargar herramienta