logo

Decrypting iPhone Apps

ID: d75d88b9-6290-576f-9604-fbcba17df82b

STIX ID: report--d75d88b9-6290-576f-9604-fbcba17df82b

Feed Name: SensePost Blog

Date Published: 2011-10-24

Date Updated: 2026-04-29

...
...

This blog post explains a technique to convert encrypted iPhone application bundles into plaintext for analysis using a jailbroken device and tools like otool, a hex editor, GDB, IDA Pro, and ldid; it outlines Mach-O basics, determining encryption status, dumping decrypted code from memory at runtime, replacing the encrypted section with the dump, and re-signing the modified binary to run on the device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.