
iOS प्लेटफ़ॉर्म सुरक्षा और छेड़छाड़-रोधी Swift लाइब्रेरी
हमारा व्यावहारिक और पूरी तरह से ऑनलाइन कोर्स देखें: https://courses.securing.pl/courses/iase


🌏 iOS Security Suite एक उन्नत और उपयोग में आसान प्लेटफ़ॉर्म सुरक्षा और एंटी-टैम्परिंग लाइब्रेरी है जो पूरी तरह Swift में लिखी गई है! यदि आप iOS के लिए डेवलपमेंट कर रहे हैं और OWASP MASVS मानक, अध्याय v8 के अनुसार अपने ऐप को सुरक्षित रखना चाहते हैं, तो यह लाइब्रेरी आपका बहुत समय बचा सकती है। 🚀
ISS क्या पता लगाता है:
IOSSecuritySuite का उपयोग शुरू करने के 4 तरीके हैं
अपने प्रोजेक्ट में IOSSecuritySuite/*.swift फ़ाइलें जोड़ें
pod 'IOSSecuritySuite'
github "securing/IOSSecuritySuite"
.package(url: "https://github.com/securing/IOSSecuritySuite.git", from: "1.5.0")
अपने प्रोजेक्ट में ISS जोड़ने के बाद, आपको अपनी मुख्य Info.plist को भी अपडेट करना होगा। जेलब्रेक डिटेक्शन मॉड्यूल में एक जाँच है जो canOpenURL(_:) विधि का उपयोग करती है और आवश्यकता है उन URLs को निर्दिष्ट करने की जो क्वेरी की जाएंगी।
<key>LSApplicationQueriesSchemes</key>
<array>
<string>undecimus</string>
<string>sileo</string>
<string>zbra</string>
<string>filza</string>
</array>
विवरण के लिए हमारा EULA लाइसेंस देखें।
TLDR: यदि आपकी कंपनी में कार्यरत हैं:
यदि आप iOS Security Suite का उपयोग करने वाला एक मॉड्यूल बेचना चाहते हैं (जो सीधे आपके ऐप में उपयोग नहीं किया गया है) - 10k EUR/वर्ष
iOS Security Suite का उपयोग iOS/iPadOS पर किया जाना है। इसे Apple Silicon वाले Macs पर उपयोग नहीं किया जाना चाहिए।
if IOSSecuritySuite.amIJailbroken() {
print("यह डिवाइस जेलब्रोकन है")
} else {
print("यह डिवाइस जेलब्रोकन नहीं है")
}
let jailbreakStatus = IOSSecuritySuite.amIJailbrokenWithFailMessage()
if jailbreakStatus.jailbroken {
print("यह डिवाइस जेलब्रोकन है")
print("क्योंकि: \(jailbreakStatus.failMessage)")
} else {
print("यह डिवाइस जेलब्रोकन नहीं है")
}
फेलमैसेज एक स्ट्रिंग है जिसमें अल्पविराम से अलग किए गए संकेतक होते हैं जैसा कि नीचे दिए गए उदाहरण में दिखाया गया है:
sileo:// URL scheme detected, Suspicious file exists: /Library/MobileSubstrate/MobileSubstrate.dylib, Fork was able to create a new process
let jailbreakStatus = IOSSecuritySuite.amIJailbrokenWithFailedChecks()
if jailbreakStatus.jailbroken {
if (jailbreakStatus.failedChecks.contains { $0.check == .existenceOfSuspiciousFiles }) && (jailbreakStatus.failedChecks.contains { $0.check == .suspiciousFilesCanBeOpened }) {
print("यह वास्तविक जेलब्रोकन डिवाइस है")
}
}
let amIDebugged: Bool = IOSSecuritySuite.amIDebugged()
IOSSecuritySuite.denyDebugger()
let runInEmulator: Bool = IOSSecuritySuite.amIRunInEmulator()
if IOSSecuritySuite.amIReverseEngineered() {
print("इस डिवाइस पर रिवर्स इंजीनियरिंग के सबूत हैं")
} else {
print("इस डिवाइस पर रिवर्स इंजीनियरिंग के सबूत नहीं हैं")
}
let reverseStatus = IOSSecuritySuite.amIReverseEngineeredWithFailedChecks()
if reverseStatus.reverseEngineered {
// अधिक जानकारी के लिए reverseStatus.failedChecks देखें
}
अब आप यह भी पता लगा सकते हैं कि कोई ऐप VPN से कनेक्ट है या नहीं
let amIProxied: Bool = IOSSecuritySuite.amIProxied(considerVPNConnectionAsProxy: true)
let amIInLockdownMode: Bool = IOSSecuritySuite.amIInLockdownMode()
let amIRuntimeHooked: Bool = amIRuntimeHook(dyldWhiteList: dylds, detectionClass: SomeClass.self, selector: #selector(SomeClass.someFunction), isClassMethod: false)
// यदि हम Swift फ़ंक्शन के सिंबल हुक को अस्वीकार करना चाहते हैं, तो हमें उस फ़ंक्शन का मैंगल्ड नाम पास करना होगा
denySymbolHook("$s10Foundation5NSLogyySS_s7CVarArg_pdtF") // NSLog फ़ंक्शन के लिए हुकिंग अस्वीकार करना
NSLog("Hello Symbol Hook")
denySymbolHook("abort")
abort()
// फ़ंक्शन घोषणा
func someFunction(takes: Int) -> Bool {
return false
}
// FunctionType परिभाषित करना : @convention(thin) एक "पतले" फ़ंक्शन संदर्भ को इंगित करता है, जो बिना किसी विशेष "self" या "context" पैरामीटर के Swift कॉलिंग कन्वेंशन का उपयोग करता है।
typealias FunctionType = @convention(thin) (Int) -> (Bool)
// उस फ़ंक्शन का पॉइंटर पता प्राप्त करना जिसे हम सत्यापित करना चाहते हैं
func getSwiftFunctionAddr(_ function: @escaping FunctionType) -> UnsafeMutableRawPointer {
return unsafeBitCast(function, to: UnsafeMutableRawPointer.self)
}
let funcAddr = getSwiftFunctionAddr(someFunction)
let amIMSHooked = IOSSecuritySuite.amIMSHooked(funcAddr)
// फ़ंक्शन घोषणा
func denyDebugger(value: Int) {
}
// FunctionType परिभाषित करना : @convention(thin) एक "पतले" फ़ंक्शन संदर्भ को इंगित करता है, जो बिना किसी विशेष "self" या "context" पैरामीटर के Swift कॉलिंग कन्वेंशन का उपयोग करता है।
typealias FunctionType = @convention(thin) (Int)->()
// मूल फ़ंक्शन का पता प्राप्त करना
let funcDenyDebugger: FunctionType = denyDebugger
let funcAddr = unsafeBitCast(funcDenyDebugger, to: UnsafeMutableRawPointer.self)
if let originalDenyDebugger = denyMSHook(funcAddr) {
// मूल फ़ंक्शन को 1337 Int आर्गुमेंट के साथ कॉल करें
unsafeBitCast(originalDenyDebugger, to: FunctionType.self)(1337)
} else {
denyDebugger()
}
// निर्धारित करें कि एप्लिकेशन के साथ छेड़छाड़ की गई है या नहीं
if IOSSecuritySuite.amITampered([.bundleID("biz.securing.FrameworkClientApp"),
.mobileProvision("2976c70b56e9ae1e2c8e8b231bf6b0cff12bbbd0a593f21846d9a004dd181be3"),
.machO("IOSSecuritySuite", "6d8d460b9a4ee6c0f378e30f137cebaf2ce12bf31a2eef3729c36889158aa7fc")]).result {
print("मेरे साथ छेड़छाड़ की गई है।")
}
else {
print("मेरे साथ छेड़छाड़ नहीं की गई है।")
}