Pentesting iOS and Android: Prove It or Delete It
Mobile pentesting has a guesswork problem. A tool flags something, a screenshot goes into a report, and nobody can say whether it’s actually exploitable. My rule, and the idea behind my “Prove or Delete” talk, is simple: if I can’t prove it, it doesn’t go in the report.
Start with the same questions on both platforms
Before touching a tool, I want to know what the app stores, what it sends, and what it trusts. The answers look different on each platform, but the questions stay the same.
- Storage: what lands on disk, and who can read it?
- Network: what leaves the device, and is it validated end to end?
- Trust: what does the app assume about the device, the user and the server?
- Secrets: is anything in the binary that shouldn’t be?
Android: the APK is an open book
Android makes the first step easy because an APK is just an archive you can take apart. Decompile it, read the manifest, and look at exported components, backup flags, hardcoded keys and custom URL handling. A lot of the CVE-level bugs I’ve found started with reading what the app declares it will accept. I go deeper on this in my BSides Sydney talk, “Inside the APK”.
iOS: the walls are higher, so evidence matters more
iOS gives you less to work with out of the box. You usually need a jailbroken or instrumented device to see runtime behaviour, and the platform’s protections (sandboxing, Keychain, code signing, the Secure Enclave) are good enough that a lazy finding falls apart quickly. When a finding survives on iOS, it tends to be real. That’s also why I care about what happens below the app layer, which is what “Unbreaking the iPhone” covered.
Prove or delete
For every finding I want three things:
- A reproduction: the exact steps, on a clean device, that anyone can follow.
- Evidence: logs, captured traffic or extracted data that shows the impact.
- A real impact statement: what an attacker gets, not what a scanner thinks.
If I can’t produce all three, the finding gets deleted or downgraded to a note. Reports get shorter, and the ones that remain get fixed.
Where I learned the habit
My day job is forensics, where “trust me” evidence doesn’t work. A timeline either supports a claim or it doesn’t. Pentesting gets better when you hold it to the same standard.
Slides for the related talks are on the talks page.