逆向工程可分为四步:砸壳、dump、hook、重签
越狱:使用http://Checkra1n 工具越狱(支持iOS12以上设备)
安装checkra1n成功,安装cydia
添加cydia软件源:https://www.itpwd.com/272.html
获取app安装包: https://juejin.im/post/5de7cd1a51882512431678ee
openSSH的root密码默认为:alpine
砸壳:
dumpdecrypted: https://github.com/AloneMonkey/dumpdecrypted
class-dump: http://stevenygard.com/projects/class-dump/
class-dump 拷贝到 /usr/local/bin(/usr/bin不能进行增删)
http://www.alonemonkey.com/2018/01/30/frida-ios-dump/
安装frida:pip3 install frida-tools -i https://pypi.mirrors.ustc.edu.cn/simple/
校验是否安装成功:frida-ps -U