Physical Device Setup
A physical iPhone/iPad is essential for realistic testing: real hardware security features, true ATS behavior, biometric prompts, and actual network stack quirks. This page walks through preparing a physical device for an assessment.
Enable Developer Mode
Since iOS 16, Developer Mode is a separate toggle that gates debugger/simulator-style tooling on physical devices. It is a privacy gate — not a jailbreak.
- Settings > Privacy & Security > Developer Mode > Enable.
- The device reboots once and asks you to confirm.
- Required before Frida gadget,
idevicedebug, or profiling tools will attach. - If the option is missing, install the "Developer" tooling once via Xcode (Window > Devices and Simulators, connect the device, let Xcode pair it).
Trust the Computer
Trusting the host is what unlocks USB access via libimobiledevice.
- Plug the device into the Mac via USB.
- Unlock the device; a "Trust This Computer?" dialog appears.
- Tap Trust and enter the passcode.
- On the Mac, the device shows up in Xcode and in
idevice_id -l.
idevice_id -l # UDID should now appear
Network Proxy Setup
To intercept traffic you point the device at Burp.
- On the device: Settings > Wi-Fi > (i) next to your network.
- Set HTTP Proxy > Manual.
- Host: the Mac's LAN IP, Port:
8080(Burp's default listener). - Configure Burp: Proxy > Options > Proxy Listeners > add
All interfaceson8080. - Verify the device can reach the host:
http://<mac-ip>:8080should serve the Burp page.
# Find the Mac's LAN IP for the proxy config
ifconfig en0 | grep "inet "
Install a Test App
Use ideviceinstaller to push an IPA directly over USB (no App Store needed).
ideviceinstaller -i app.ipa # install
ideviceinstaller -l # list installed bundle IDs
ideviceinstaller -u <bundle-id> # uninstall
Jailbroken vs Non-Jailbroken
Both are viable, but they change the workflow significantly.
-
Non-jailbroken:
- No SSH, no persistent Frida server.
- Use Frida in "gadget" mode by injecting
FridaGadget.dylibinto the IPA before signing/reinstalling. - SSL pinning bypass is harder (no Cydia Substrate/tweak injection at runtime without the gadget).
- App Store apps can be extracted from the device with
ideviceinstallerorcfgutil/Apple Configurator for analysis.
-
Jailbroken (e.g., checkra1n, palera1n, Dopamine, rootless or rootful):
- Gives you SSH (
root/mobile) and a persistent Frida server. - Cydia/Sileo tweak injection makes SSL pinning and JB-detection bypass trivial.
- You can edit
/etc/hosts, dump keychain items, and read app data under the container paths. - Comes with the risk of detection: many apps check for jailbreak and will refuse to run or change behavior. That itself becomes part of the test.
- Gives you SSH (
Device Hygiene
- Use a dedicated test device, not your daily driver.
- Keep the iOS version documented; tooling behavior varies across major versions.
- For jailbroken devices, prefer rootless jailbreaks on recent iOS if possible — fewer app-compatibility surprises.
- Reset the device ("Erase All Content and Settings") between unrelated clients.
Post-Setup Checklist
- Developer Mode enabled and confirmed.
- Computer trusted (no prompt on re-plug).
- Burp proxy reachable from the device.
- Burp CA installed and trusted (see the Burp Suite page).
- At least one test app installed via
ideviceinstaller. - If jailbroken: SSH verified and Frida server running.