Skip to main content

Physical Device Setup

A physical iPhone/iPad is essential for realistic testing: real hardware security features, true ATS behavior, biometric prompts, and actual network stack quirks. This page walks through preparing a physical device for an assessment.

Enable Developer Mode​

Since iOS 16, Developer Mode is a separate toggle that gates debugger/simulator-style tooling on physical devices. It is a privacy gate — not a jailbreak.

  • Settings > Privacy & Security > Developer Mode > Enable.
  • The device reboots once and asks you to confirm.
  • Required before Frida gadget, idevicedebug, or profiling tools will attach.
  • If the option is missing, install the "Developer" tooling once via Xcode (Window > Devices and Simulators, connect the device, let Xcode pair it).

Trust the Computer​

Trusting the host is what unlocks USB access via libimobiledevice.

  • Plug the device into the Mac via USB.
  • Unlock the device; a "Trust This Computer?" dialog appears.
  • Tap Trust and enter the passcode.
  • On the Mac, the device shows up in Xcode and in idevice_id -l.
idevice_id -l          # UDID should now appear

Network Proxy Setup​

To intercept traffic you point the device at Burp.

  • On the device: Settings > Wi-Fi > (i) next to your network.
  • Set HTTP Proxy > Manual.
  • Host: the Mac's LAN IP, Port: 8080 (Burp's default listener).
  • Configure Burp: Proxy > Options > Proxy Listeners > add All interfaces on 8080.
  • Verify the device can reach the host: http://<mac-ip>:8080 should serve the Burp page.
# Find the Mac's LAN IP for the proxy config
ifconfig en0 | grep "inet "

Install a Test App​

Use ideviceinstaller to push an IPA directly over USB (no App Store needed).

ideviceinstaller -i app.ipa      # install
ideviceinstaller -l # list installed bundle IDs
ideviceinstaller -u <bundle-id> # uninstall

Jailbroken vs Non-Jailbroken​

Both are viable, but they change the workflow significantly.

  • Non-jailbroken:

    • No SSH, no persistent Frida server.
    • Use Frida in "gadget" mode by injecting FridaGadget.dylib into the IPA before signing/reinstalling.
    • SSL pinning bypass is harder (no Cydia Substrate/tweak injection at runtime without the gadget).
    • App Store apps can be extracted from the device with ideviceinstaller or cfgutil/Apple Configurator for analysis.
  • Jailbroken (e.g., checkra1n, palera1n, Dopamine, rootless or rootful):

    • Gives you SSH (root/mobile) and a persistent Frida server.
    • Cydia/Sileo tweak injection makes SSL pinning and JB-detection bypass trivial.
    • You can edit /etc/hosts, dump keychain items, and read app data under the container paths.
    • Comes with the risk of detection: many apps check for jailbreak and will refuse to run or change behavior. That itself becomes part of the test.

Device Hygiene​

  • Use a dedicated test device, not your daily driver.
  • Keep the iOS version documented; tooling behavior varies across major versions.
  • For jailbroken devices, prefer rootless jailbreaks on recent iOS if possible — fewer app-compatibility surprises.
  • Reset the device ("Erase All Content and Settings") between unrelated clients.

Post-Setup Checklist​

  • Developer Mode enabled and confirmed.
  • Computer trusted (no prompt on re-plug).
  • Burp proxy reachable from the device.
  • Burp CA installed and trusted (see the Burp Suite page).
  • At least one test app installed via ideviceinstaller.
  • If jailbroken: SSH verified and Frida server running.