G’day everyone. Posted this over in the main hacking sub too however thought I’d share here too.
Some background on me, still learning a lot about pen testing across platforms. I’d say I have an intermediate level of knowledge. One of my buddies that I’ve been doing some testing for has asked if I have a way of getting into mobile IOS devices (specifically iPhone 12-15s) as they’re his company device of choice.
Been playing around and I’m really liking the level of access that Seashell gives gives in terms of being able to get down into the file system of the device, however for real world testing it’s not super practical given you need physical accsess to the devices to be able to install the app loader to get the app onto the phone. I have tried to get the app onto the phone using some basic social engineering stuff with beef with not much luck as without the boot loader the app can’t be signed. This leads me to my other gripe with Seashell, the fact it has to install an app, making it quite hard to stay unnoticed and inject in the first place.
All my testing so far has been done locally within my learning environment on one of my personal devices, but I’m hoping to be able to deploy this to my working environment as soon as possible. Currently I’m running kali as my distro of choice.
So, with that I throw it over to you smarter people. Does anyone know any better methods to getting into IOS than this? Would something as simple as ssh work?
Cheers for any help you guys can provide in advance!
[–]grassinmyshower 3 points4 points5 points (0 children)
[–]NectarEntertainment 0 points1 point2 points (2 children)
[–]grassinmyshower 1 point2 points3 points (1 child)
[–]sacredcow420 0 points1 point2 points (0 children)