iblessing是一个iOS安全利用工具包,主要包括应用信息收集、静态分析和动态分析。可用于逆向工程、二进制分析和漏洞挖掘。
☠️ ██╗██████╗ ██╗ ███████╗███████╗███████╗██╗███╗ ██╗ ██████╗ ██║██╔══██╗██║ ██╔════╝██╔════╝██╔════╝██║████╗ ██║██╔════╝ ██║██████╔╝██║ █████╗ ███████╗███████╗██║██╔██╗ ██║██║ ███╗ ██║██╔══██╗██║ ██╔══╝ ╚════██║╚════██║██║██║╚██╗██║██║ ██║ ██║██████╔╝███████╗███████╗███████║███████║██║██║ ╚████║╚██████╔╝ ╚═╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝╚═╝╚═╝ ╚═══╝ ╚═════╝
iblessing 是一个 iOS 安全利用工具包,主要包括应用信息收集、静态分析和动态分析。iblessing 基于 unicorn engine、capstone engine 和 keystone engine。🔥 跨平台:已在 macOS 和 Ubuntu 上测试。
iOS 应用静态信息提取,包括元数据、深层链接、URL 等。
Mach-O 解析器和 dyld 符号绑定模拟器
Objective-C 类实现和解析
扫描器对 arm64 汇编代码进行动态分析,发现关键信息或攻击面
扫描器使用 unicorn 部分模拟 Mach-O arm64 代码执行并发现一些特征
生成器可以对扫描器的报告进行二次处理,启动查询服务器或为 IDA 生成脚本
超级 objc_msgSend 交叉引用扫描器 😄
测试
Android 扫描器支持
诊断日志
更灵活的扫描器基础设施以支持新的扫描器插件
如果需要关于 iblessing 或其任何相关内容的支持,你可以:
⚠️⚠️⚠️ 二进制扫描器需要 12GB 的虚拟内存空间来加载 mach-o 文件,但不会消耗这么多。因此你需要确保工作机器的物理内存大于 12GB,或者通过交换文件机制确保可分配的虚拟内存大于 12GB。
要开始编译 iblessing,请按照以下步骤操作:``` git clone --recursive -j4 https://github.com/Soulghost/iblessing cd iblessing ./compile-cmake.sh
## 快捷方式
- [基本概念](https://github.com/Soulghost/iblessing#basic-concepts)
- 扫描器
- [扫描应用信息](https://github.com/Soulghost/iblessing#scan-for-appinfos) ⚠️ 目前在 Linux 上不可用
- [扫描类引用](https://github.com/Soulghost/iblessing#scan-for-class-xrefs)
- [扫描所有 objc_msgSend 引用](https://github.com/Soulghost/iblessing#scan-for-all-objc_msgsend-xrefs)
- [扫描简单符号包装器](https://github.com/Soulghost/iblessing/blob/features/anti_wrapper/README.md#scan-for-symbol-wrappers)
- 生成器
- [生成 objc_msgSend 引用查询服务器](https://github.com/Soulghost/iblessing#generate-objc_msgsend-xrefs-query-server)
- [生成 objc_msgSend 引用的 IDA 脚本](https://github.com/Soulghost/iblessing#generate-ida-scripts-for-objc_msgsend-xrefs)
- [生成 objc 函数包装器重命名和原型修改的 IDA 脚本](https://github.com/Soulghost/iblessing/blob/features/anti_wrapper/README.md#genereate-ida-script-for-objc-runtime-function-rename-and-prototype-modification)
***如果出现任何错误,你可以手动编译 capstone 和 unicorn,然后将 libcapstone.a 和 libunicorn.a 拖入 Xcode 项目的 vendor/libs 目录。***
如果一切运行成功,你可以在构建目录中找到二进制文件:```
> ls ./build
iblessing
> file ./build/iblessing
./build/iblessing: Mach-O 64-bit executable x86_64
$ iblessing -h
☠️
██╗██████╗ ██╗ ███████╗███████╗███████╗██╗███╗ ██╗ ██████╗
██║██╔══██╗██║ ██╔════╝██╔════╝██╔════╝██║████╗ ██║██╔════╝
██║██████╔╝██║ █████╗ ███████╗███████╗██║██╔██╗ ██║██║ ███╗
██║██╔══██╗██║ ██╔══╝ ╚════██║╚════██║██║██║╚██╗██║██║ ██║
██║██████╔╝███████╗███████╗███████║███████║██║██║ ╚████║╚██████╔╝
╚═╝╚═════╝ ╚══════╝╚══════╝╚══════╝╚══════╝╚═╝╚═╝ ╚═══╝ ╚═════╝
[] iblessing iOS Security Exploiting Toolkit Beta 0.1.1 (http://blog.asm.im) [] Author: Soulghost (高级页面仔) @ (https://github.com/Soulghost)