1 year ago

#102899

test-img

paragdulam

How to find out in source code the function names the Xcode's otool outputs for you?

I have supposedly 2 security vulnerabilities in the iOS app I developed. This medium article enlisted both issues I faced.

Look for:

Usage of Insecure Random Number Generator

and

Usage of Banned/Deprecated APIs

Those are the two issues I faced in my iOS app as well. I used Xcode's and ran the terminal command like shown in the link above and saw that these deprecated methods like _random and insecure methods like _memcpy and _strlen are being used in the app.

What I want to do here is to understand where in my source code I am using these methods. I have searched my entire source code of my Xcode Project, I don't have it used or called directly.

otool outputs in assembly language format and shows random address

How can I find out in source code where I must be using these methods? or decipher the assembly code to ObjC source code? so that I can remove that code and use a better alternative which in turn will remove the security vulnerability.

ios

objective-c

xcode

security

otool

0 Answers

Your Answer

Accepted video resources