Penetration Testing mailing list archives

Re: Iphone pen test?


From: Chris Clymer <cclymer () gmail com>
Date: Fri, 25 Jun 2010 13:20:06 -0400

If at all possible you probably want to try to get access to a mac and install xcode and the official iphone SDK (both free). These come with loads of dev tools, including an iphone emulator which you can test code on with a lot more debug info available.



On Jun 22, 2010, at 2:31 PM, Pietro Riva <daphiel () gmail com> wrote:

Hi,
look for pirni (jailbroken only) in cydia/rock. It's a
man-in-the-middle sniffer that can easy take a pcap file on your
device.
I've also successfully decoded a VoIP call into Wireshark.


2010/6/21 <yasser.alruhaily () gmail com>

Hi all,

i have an assignment to pentest iphone application. how can I intercept the data before send it out to the server?

Is there any application could run in iphone as intercepting proxy?
how can i check buffer over flow errors?

thanx
YassEr

--- --------------------------------------------------------------------- This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
--- ---------------------------------------------------------------------


--- --------------------------------------------------------------------- This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
--- ---------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------


Current thread: