Skip to main content

Mobile Hacking Lab Setup

A mobile lab is a stack: host tools, a test target (device or simulator), an intercepting proxy, and the instrument tools that tie them together. This page describes how the pieces fit and the traffic flow through the lab.

Components​

  • Host: macOS (or Parrot on Linux). Runs Burp, Frida tools, Objection, MobSF, and the USB drivers.
  • Target: physical device (jailbroken or not) or iOS Simulator. The app under test lives here.
  • Proxy: Burp Suite listening on the host, forwarding to the internet.
  • Instrumentation: Frida/objection attach to the running app to patch behavior (bypass pinning, hook methods).
  • Analysis: MobSF for static review of the IPA; manual review for dynamic results.

Traffic Flow​

Normal flow when the device is pointed at Burp:

App (device)
-> HTTP proxy setting (manual Wi-Fi proxy or simulator global proxy)
-> Burp Suite on host (127.0.0.1:8080 or 0.0.0.0:8080 for device)
-> Internet

For USB-tunneled devices (jailbroken with SSH, or no Wi-Fi), iproxy carries the traffic:

App (device) --USB--> usbmuxd/iproxy --local--> Burp on host

For instrumentation, Frida works over the same USB channel:

host: frida -U          <->  device: frida-server (or gadget)
host: objection -g <-> device: gadget

Common Configurations​

  • Physical jailbroken device + USB:

    • iproxy 2222 22 opens a local SSH tunnel to the device.
    • Burp listener on 0.0.0.0:8080; device proxy points at the host LAN IP.
    • frida-server running on the device; host uses frida-ps -U.
  • Physical non-jailbroken device:

    • No SSH. Frida runs as a gadget injected into the IPA before install.
    • Proxy only; no runtime patching without rebuilding the IPA.
    • App extraction via ideviceinstaller or cfgutil for MobSF upload.
  • Simulator only:

    • Everything local: Burp on 127.0.0.1:8080, Frida targets simulator processes directly.
    • Fastest iteration; results must be re-validated on hardware.

Burp Listener Setup​

# Burp: Proxy > Options > Proxy Listeners
# Add listener: All interfaces, port 8080 (for physical device over LAN)
# Add listener: 127.0.0.1, port 8080 (for simulator / localhost)

Check the listener binds on the right interface and that the OS firewall allows inbound on 8080.

# Confirm Burp is listening
nc -z 127.0.0.1 8080 && echo "Burp is up on localhost"

# Confirm from the device's perspective once proxy is configured
# Browse to http://<mac-ip>:8080 on the device

Certificate Trust Chain​

For HTTPS interception, install and trust the Burp CA on the target:

  • Install: open http://<burp-ip>:8080 on the device, download cacert.der, install the profile.
  • Trust: Settings > General > About > Certificate Trust Settings > Enable Full Trust.
  • Simulator: drag the .der onto the Simulator window, same trust flow inside Settings.

If the app pins its certificate, Burp alone won't see traffic until you bypass pinning with Frida/objection.

Lab Wiring Cheatsheet​

PiecePhysical (jailbroken)Physical (stock)Simulator
SSHiproxy 2222 22n/an/a
Fridafrida-server on device, -Ugadget in IPAhost, no -U
ProxyLAN IP :8080LAN IP :8080127.0.0.1 :8080
Static analysisMobSF on extracted IPAMobSF on extracted IPAMobSF on build

Order of Operations for an Assessment​

  1. Extract or obtain the target IPA.
  2. Run MobSF static analysis while you set up the environment.
  3. Install the app on the target (device or simulator).
  4. Point the target at Burp, install/trust the CA.
  5. Run the app, observe baseline HTTP/HTTPS traffic.
  6. Enable instrumentation; bypass pinning/JB-detection as needed.
  7. Drill into interesting endpoints with repeater; document everything.