iOS security attack and defense series summary

iOS App Reverse Engineering

Know the column:

Book Recommendations:

iOS jailbreak program development

  1. Tools
  2. Build and deploy
  3. Your First Tweak
  4. Summarize

iOS Application Security

  1. Build a mobile penetration testing platform
  2. Get class information for iOS application
  3. 理解Objective-C Runtime
  4. Runtime Analysis with Cycript (Yahoo Weather App)
  5. Advanced Techniques for Runtime Analysis with Cycript (Yahoo Weather Application
  6. New Security Features in iOS 7
  7. How to install an app to a device without a certificate
  8. Method Swizzling with Cycript
  9. Analyzing the Security of iOS Applications with Snoop-it
  10. iOS file system and forensics
  11. Analyze network traffic using HTTP/HTTPS
  12. Export Keychain data
  13. Start custom Ramdisk using Sogeti Data Protection tools
  14. Gather information with Sogeti Data Protection tools
  15. Static Analysis of iOS Apps with iNalyzer
  16. Dynamic Analysis of iOS Apps with iNalyzer
  17. Black-box testing of iOS apps with Introspy
  18. Detect custom signatures with Introspy
  19. Using Introspy in your program
  20. Local data storage and its security (NSUserDefaults, CoreData, Sqlite, Plist files)
  21. ARM and GDB basics
  22. Runtime analysis and manipulation with GDB
  23. Against runtime analysis and manipulation
  24. Jailbreak detection and bypass
  25. iOS development security programming practice
  26. Patching iOS Apps with IDA Pro
  27. Brief summary

iOS security attack and defense

  1. Hack essential commands and tools
  2. Background daemon illegally steals user iTunesstore information
  3. Use Reveal to analyze other people's apps
  4. Prevent GDB from being attached
  5. Use Cycript to modify Alipay app runtime
  6. Use class-dump-z to analyze Alipay app
  7. Hack actual combat - lift the limit on the number of times the Alipay app is unlocked by gestures
  8. Keyboard Cache and Secure Keyboard
  9. 使用Keychain-Dumper导出keychain数据
  10. 二进制和资源文件自检
  11. Hack实战——探究支付宝app手势密码
  12. iOS7的动态库注入
  13. 数据擦除
  14. Hack实战——支付宝app手势密码校验欺骗
  15. 使用iNalyzer分析应用程序
  16. 使用introspy追踪分析应用程序
  17. Fishhook
  18. 数据保护API
  19. 基于脚本实现动态库注入
  20. 越狱检测的攻与防
  21. 废除应用程序的ASLR特性
  22. static和被裁的符号表

苹果关于安全的文档

  1. Security Overview
  2. Secure Coding Guide
  3. iOS Security
  4. Cryptographic Services Guide
  5. Secure Transport Reference
  6. CFNetwork Programming Guide
  7. Certificate, Key, and Trust Services Reference
  8. Certificate, Key, and Trust Services Programming Guide
  9. Keychain Services Reference
  10. Keychain Services Programming Guide

 

Posted by TracyYih - 2014-02-14
如需转载,请注明: 本文来自 Esoft Mobile

Guess you like

Origin http://10.200.1.11:23101/article/api/json?id=326655609&siteId=291194637