Burp Suite
Burp Suite is the primary intercepting proxy for iOS testing. This page covers proxy configuration on the device, installing and trusting the Burp CA, and the ATS bypass notes you will need when apps refuse to talk over plain HTTP.
Proxy Configuration
On the physical device (jailbroken or not):
- Settings > Wi-Fi > tap the network (i).
- Scroll to HTTP Proxy > Manual.
- Server: the Mac's LAN IP.
- Port:
8080(Burp's default listener). - Save and reconnect to the network.
On the simulator:
- Burp listener on
127.0.0.1:8080. - The simulator shares the Mac's loopback, so the app can reach the host directly.
- Set the proxy globally via
xcrun simctl spawn ... defaults writeor via the Simulator's Settings > Wi-Fi if supported.
# Burp listener for a physical device: bind to all interfaces
# Burp > Proxy > Options > Proxy Listeners > Add > All interfaces, port 8080
# Verify the listener
nc -z 127.0.0.1 8080 && echo OK
Install the Burp CA Certificate
Burp generates its own CA on first run. Export and install it on the device.
- Burp > Proxy > Options > Import/Export CA Certificate > Certificate in DER format.
- Serve it:
cp cacert.der /tmp/then run a static server, or navigate the device tohttp://<mac-ip>:8080and downloadcacert.derfrom the page. - On the device: open the downloaded profile, Settings > General > Profiles > Install.
- On the simulator: drag
cacert.deronto the Simulator window, then install from Settings > General > Profiles.
# Serve the DER from the host so the device can fetch it
cd /tmp && python3 -m http.server 9999
# Then on the device open: http://<mac-ip>:9999/cacert.der
Trust the Certificate (the important part)
Installing the profile alone is not enough on modern iOS. You must also enable full trust, otherwise HTTPS interception fails silently.
- iOS: Settings > General > About > Certificate Trust Settings.
- Find the Burp CA (e.g., "PortSwigger CA").
- Toggle "Enable Full Trust for Root Certificates".
- Confirm the prompt.
Verify it worked:
- On the device open
https://example.comin Safari. - In Burp, the request should appear in the HTTP history.
If traffic is not showing:
- Check the proxy host/port are correct and the firewall allows inbound
8080. - Confirm the CA was installed in the device keychain, not just downloaded.
- Confirm full trust is enabled (the trust toggle).
ATS (App Transport Security)
ATS blocks plaintext HTTP and requires TLS 1.2+ with forward secrecy. Two ways around it during a test.
- App-side: the app's
Info.plistmust allow arbitrary loads or add an exception domain.
<key>NSAppTransportSecurity</key>
<dict>
<key>NSAllowsArbitraryLoads</key>
<true/>
</dict>
- Attack-side: since you control the environment, patch the IPA's
Info.plistwith the above keys, re-sign, and reinstall. This is a legitimate test procedure for your own lab apps.
# Patch Info.plist in the decrypted/extracted IPA
/usr/libexec/PlistBuddy -c "Add :NSAppTransportSecurity:NSAllowsArbitraryLoads bool true" Payload/App.app/Info.plist
codesign -f -s - --deep Payload/App.app
# Re-zip and install with ideviceinstaller
SSL Pinning vs ATS
- ATS is a default transport policy — apps can and do override it.
- SSL pinning is an app-enforced trust anchor (public key or certificate pin). Burp's CA will be rejected even if trusted, because the app checks its own pin.
- When pinning is present, you need Frida/objection to bypass it (see the Frida and Objection pages) or patch the app binary.
Burp Tips for iOS Testing
# Use Match and Replace to rewrite Host headers if an app hardcodes an IP
# Burp > Proxy > Options > Match and Replace
# Example: ^api\.example\.com -> <burp-ip>
# Set scope to the target to keep history clean
# Burp > Target > Scope
# Save a project for long-running assessments
burpsuite --project-file assessment.burp
Gotchas
- The device must rejoin the Wi-Fi after changing the proxy.
- Some apps only proxy when a specific entitlement or network condition exists — verify with
idevicesyslogfor connection errors. - Non-jailbroken devices cannot bypass pinning via tweaks; you must rebuild the IPA with a gadget.
- Always test both HTTP and HTTPS flows; mixed traffic is common.