MASTG-DEMO-0042: Runtime Use of LAContext.evaluatePolicy with Frida
Download MASTG-DEMO-0042 IPA Open MASTG-DEMO-0042 Folder Build MASTG-DEMO-0042 IPA
Sample¶
This demo uses the same sample as Uses of LAContext.evaluatePolicy with r2.
| ../MASTG-DEMO-0041/MastgTest.swift | |
|---|---|
1 2 3 4 5 6 7 8 910111213141516171819202122232425262728293031323334353637383940414243444546474849 | |
Steps¶
- Install the app on a device ( Installing Apps)
- Make sure you have Frida for iOS installed on your machine and the frida-server running on the device
- Run
run.shto spawn your app with Frida - Click theStart button
- Stop the script by pressing
Ctrl+C
12 | |
1 2 3 4 5 6 7 8 91011121314151617181920212223242526272829 | |
Observation¶
| output.txt | |
|---|---|
1 2 3 4 5 6 7 8 9101112 | |
The output reveals the use ofLAContext.evaluatePolicy(0x1, ...) in the app. Policy0x1 is.deviceOwnerAuthenticationWithBiometrics.
Evaluation¶
The test fails because the output only shows calls to biometric verification with LocalAuthentication API and no calls to any Keychain APIs requiring user presence (SecAccessControlCreateWithFlags).