finds.dev← search

// the find

LaurieWired/iOS_Reverse_Engineering

★ 563 · Python · updated Jan 2024

The iOS IPA file Reverse Engineering reference

A reference collection for iOS IPA reverse engineering: a wiki guide plus a handful of practical artifacts — Ghidra scripts for Swift name demangling and swizzling detection, and sample obfuscated IPAs to practice against. Aimed at people starting out in iOS RE who want something more hands-on than a blog post.

The two Ghidra scripts solve narrow, real problems (Swift symbol demangling and detecting Objective-C method swizzling) rather than being generic tutorial filler. The example IPAs cover distinct obfuscation techniques (control flow flattening, anti-tampering, swizzling) so you can practice against actual obfuscated binaries instead of just reading theory. Keeping the deep-dive content in the wiki instead of the repo keeps the repo itself small and focused on runnable artifacts.

Despite being tagged Python, there are only two scripts in the whole repo — most of the value is in the wiki, which isn't versioned alongside the code and could drift or disappear independent of this repo. No instructions on Ghidra version compatibility or how to load the scripts, so you're on your own for setup. No commits since January 2024, so nothing here accounts for Swift ABI or tooling changes since then. No LICENSE file, which matters if you want to adapt the scripts into your own tooling.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →