Mobile Hacking Lab Setup
A mobile lab is a stack: host tools, a test target (device or simulator), an intercepting proxy, and the instrument tools that tie them together. This page describes how the pieces fit and the traffic flow through the lab.
Components
- Host: macOS (or Parrot on Linux). Runs Burp, Frida tools, Objection, MobSF, and the USB drivers.
- Target: physical device (jailbroken or not) or iOS Simulator. The app under test lives here.
- Proxy: Burp Suite listening on the host, forwarding to the internet.
- Instrumentation: Frida/objection attach to the running app to patch behavior (bypass pinning, hook methods).
- Analysis: MobSF for static review of the IPA; manual review for dynamic results.
Traffic Flow
Normal flow when the device is pointed at Burp:
App (device)
-> HTTP proxy setting (manual Wi-Fi proxy or simulator global proxy)
-> Burp Suite on host (127.0.0.1:8080 or 0.0.0.0:8080 for device)
-> Internet
For USB-tunneled devices (jailbroken with SSH, or no Wi-Fi), iproxy carries the traffic:
App (device) --USB--> usbmuxd/iproxy --local--> Burp on host
For instrumentation, Frida works over the same USB channel:
host: frida -U <-> device: frida-server (or gadget)
host: objection -g <-> device: gadget
Common Configurations
-
Physical jailbroken device + USB:
iproxy 2222 22opens a local SSH tunnel to the device.- Burp listener on
0.0.0.0:8080; device proxy points at the host LAN IP. frida-serverrunning on the device; host usesfrida-ps -U.
-
Physical non-jailbroken device:
- No SSH. Frida runs as a gadget injected into the IPA before install.
- Proxy only; no runtime patching without rebuilding the IPA.
- App extraction via
ideviceinstallerorcfgutilfor MobSF upload.
-
Simulator only:
- Everything local: Burp on
127.0.0.1:8080, Frida targets simulator processes directly. - Fastest iteration; results must be re-validated on hardware.
- Everything local: Burp on
Burp Listener Setup
# Burp: Proxy > Options > Proxy Listeners
# Add listener: All interfaces, port 8080 (for physical device over LAN)
# Add listener: 127.0.0.1, port 8080 (for simulator / localhost)
Check the listener binds on the right interface and that the OS firewall allows inbound on 8080.
# Confirm Burp is listening
nc -z 127.0.0.1 8080 && echo "Burp is up on localhost"
# Confirm from the device's perspective once proxy is configured
# Browse to http://<mac-ip>:8080 on the device
Certificate Trust Chain
For HTTPS interception, install and trust the Burp CA on the target:
- Install: open
http://<burp-ip>:8080on the device, downloadcacert.der, install the profile. - Trust: Settings > General > About > Certificate Trust Settings > Enable Full Trust.
- Simulator: drag the
.deronto the Simulator window, same trust flow inside Settings.
If the app pins its certificate, Burp alone won't see traffic until you bypass pinning with Frida/objection.
Lab Wiring Cheatsheet
| Piece | Physical (jailbroken) | Physical (stock) | Simulator |
|---|---|---|---|
| SSH | iproxy 2222 22 | n/a | n/a |
| Frida | frida-server on device, -U | gadget in IPA | host, no -U |
| Proxy | LAN IP :8080 | LAN IP :8080 | 127.0.0.1 :8080 |
| Static analysis | MobSF on extracted IPA | MobSF on extracted IPA | MobSF on build |
Order of Operations for an Assessment
- Extract or obtain the target IPA.
- Run MobSF static analysis while you set up the environment.
- Install the app on the target (device or simulator).
- Point the target at Burp, install/trust the CA.
- Run the app, observe baseline HTTP/HTTPS traffic.
- Enable instrumentation; bypass pinning/JB-detection as needed.
- Drill into interesting endpoints with repeater; document everything.