skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
p4nda0s/reverse-skills1.1k installs

rev-ios-dump

Dump decrypted iOS app binaries (砸壳) from jailbroken devices using frida-ios-dump. Activate when the user wants to decrypt an iOS app, dump an IPA from a device, or extract a decrypted Mach-O binary for reverse engineering.

How do I install this agent skill?

npx skills add https://github.com/p4nda0s/reverse-skills --skill rev-ios-dump
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill provides a structured workflow for decrypting and dumping iOS applications from jailbroken devices for security research. It utilizes the frida-ios-dump tool from the author's own repository and leverages standard reverse engineering utilities. All identified external resources and commands are consistent with the stated purpose of mobile security analysis.

  • Socketwarn

    1 alert: gptSecurity

  • Snykfail

    Risk: HIGH · 2 issues

What does this agent skill do?

rev-ios-dump - iOS App Decryption (砸壳)

Dump decrypted iOS application binaries from jailbroken devices for security analysis and reverse engineering.


Overview

iOS apps distributed via the App Store are encrypted with Apple's FairPlay DRM. To perform static analysis (IDA/Ghidra/Hopper), the binary must first be decrypted at runtime — commonly called "砸壳" (dumping the shell). This skill uses Frida to instrument the running process and dump the decrypted Mach-O from memory.


Prerequisites

RequirementDetails
Jailbroken iOS deviceWith SSH access enabled
frida-serverInstalled and running on the device
Python 3On the host machine
frida + frida-toolspip3 install frida frida-tools
USB or network accessSSH connection to the device

Verify frida-server is Running

# Check frida-server on device via SSH
ssh mobile@<device_ip> "ps aux | grep frida-server"

# If not running, start it
ssh mobile@<device_ip> "/usr/sbin/frida-server -D &"

# Verify from host
frida-ls-devices
frida-ps -H <device_ip>

Tool: frida-ios-dump

Repo: https://github.com/P4nda0s/frida-ios-dump

Installation

git clone https://github.com/P4nda0s/frida-ios-dump.git
cd frida-ios-dump
pip3 install -r requirements.txt

# Build the TypeScript agent (required before first run)
npm install --ignore-scripts
npx frida-compile dump.ts -o dist/dump.js

Note: This version uses a TypeScript-based Frida agent. The dist/dump.js must be compiled before dump.py can run.


Step-by-Step Workflow

Step 1: Identify Target App Bundle ID

Use one of these methods on the device:

# Method 1: List running apps via Frida
frida-ps -H <device_ip> -a

# Method 2: SSH into device and check
ssh mobile@<device_ip> "find /var/containers/Bundle/Application -name Info.plist -exec plutil -p {} \; 2>/dev/null | grep CFBundleIdentifier"

Or use CocoaTop on the device to identify the running process and its Bundle ID.

Step 2: Ensure Target App is Running

The target app must be running on the device. frida-ios-dump attaches to the live process to dump decrypted memory.

Step 3: Execute Dump

cd frida-ios-dump

python3 dump.py -H <device_ip> -u mobile -P <password> <bundle_id>

Parameters:

FlagDescription
-HDevice IP address
-uSSH username (typically mobile)
-PSSH password (typically alpine on fresh jailbreak)
<bundle_id>Target app Bundle ID (e.g., app.ish.iSH)

Example:

python3 dump.py -H 192.168.1.100 -u mobile -P alpine app.ish.iSH

Step 4: Verify Output

A successful dump produces a .ipa file in the current directory:

ls -la *.ipa

# Unzip to inspect
unzip -o <app_name>.ipa -d dumped_app/

# Verify decryption — cryptid should be 0
otool -l dumped_app/Payload/<AppName>.app/<BinaryName> | grep -A4 LC_ENCRYPTION_INFO

If cryptid 0 is shown, the binary is successfully decrypted.


Troubleshooting

ErrorCauseFix
Failed to spawnApp not installed or wrong Bundle IDVerify Bundle ID with frida-ps -H <ip> -a
Unable to connect to remote frida-serverfrida-server not running or port blockedStart frida-server on device, check firewall
SSH connection refusedSSH not enabled or wrong credentialsVerify SSH access: ssh mobile@<ip>
Timeout waiting for processApp crashed or not fully launchedLaunch app manually first, then retry
frida.ServerNotRunningErrorfrida-server version mismatchMatch frida-server version to host frida version
cryptid 1 in outputDump failed, binary still encryptedEnsure app is running during dump, retry
Permission deniedSSH key/password issueCheck -u and -P flags, or use SSH key auth

Version Mismatch Fix

frida-server and host frida must be the same major version:

# Check host version
frida --version

# Download matching frida-server from:
# https://github.com/frida/frida/releases
# Choose: frida-server-<version>-ios-arm64.xz

Output Usage

After obtaining the decrypted IPA:

  1. Static analysis — Load the decrypted Mach-O into IDA/Ghidra/Hopper
  2. Class dump — Extract ObjC headers: class-dump <binary> > headers.h
  3. String analysis — Search for sensitive strings, URLs, keys
  4. Frida hooking — Use with rev-frida skill for dynamic analysis
  5. Symbol recovery — Use with rev-symbol skill for stripped binary analysis

Notes

  • The device must remain unlocked and the app must stay in the foreground during the dump process.
  • For apps with multiple frameworks, frida-ios-dump will dump all encrypted frameworks within the app bundle.
  • Some apps with advanced jailbreak detection may terminate before the dump completes — consider bypassing jailbreak detection first.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/p4nda0s/reverse-skills/rev-ios-dump">View rev-ios-dump on skillZs</a>