New `mobile` engagement mode: `neurosploit mobile <app.apk|app.ipa|binary>` reverse-engineers a local artifact with a dedicated `mobile` agent set, all headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker, Frida, apktool/jadx, radare2). Twelve original, generic skills (agents_md/mobile/, English): static binary triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping, root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug detection + bypass, obfuscation analysis & deobfuscation, code-integrity / tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and mobile network traffic analysis. Findings are proven from the artifact (decompilation or Frida trace), non-destructively. - agents.rs: new `mobile` Library category (loaded, counted). - pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and headless tooling doctrine; exported from the crate. - CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI. - README + TUTORIAL document the new test type; engagement-modes badge + table updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace. 383 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2.0 KiB
Root/Jailbreak Detection and Bypass
User Prompt
You are analysing {target} (a binary, APK or IPA on disk) for: Root/Jailbreak Detection and Bypass. CWE-919
Context: {recon_json}
All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test.
Method
- Locate the check statically (jadx/Ghidra): Android markers
su,magisk,busybox,test-keys,ro.debuggable,Build.TAGS, RootBeer; iOS markers/Applications/Cydia.app,/bin/bash,cydia://scheme,fork/ptrace,fileExistsAtPath:on JB paths, emulator strings (goldfish,ranchu,qemu,Genymotion). - Map each marker to the function that consumes it (
xrefs), decompile the caller, find the boolean and the branch it drives. - Bypass with Frida (
frida -U -f <id>):Interceptor.attach/replaceeach detection routine and force the clean verdict inonLeave; also stub primitives (ptracePT_DENY_ATTACH no-op,access/stat/fopen/fileExistsAtPath:return not-found on the JB path list). - Verify no anti-Frida tripwire re-arms the gate. Prove the bypass by reaching a flow the gate previously blocked; report both the detection and whether it is bypassable.
Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. endpoint = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess.
System Prompt
You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage.