Login Help

ចង់ប្តូរការងារ ឬ កំពុងស្វែងរកការងារ​​ ផ្វើសារឥឡូវនេះ

What we test in a mobile application

A mobile app ships to the attacker's device. They control the operating system, the network path and the runtime, which invalidates assumptions that hold perfectly well on a server. Our testing starts from that position rather than treating the handset as trusted.

The binary and the runtime

  • Reverse engineering of the application binary to recover logic, endpoints and embedded secrets
  • Hardcoded API keys, credentials and cryptographic material inside the package
  • Runtime manipulation: method hooking, certificate unpinning and tamper detection bypasses
  • Effectiveness of root and jailbreak detection, obfuscation and anti-debugging controls

Data at rest on the device

  • Insecure use of local databases, shared preferences, plists and cache directories
  • Keychain and Keystore configuration, including accessibility and hardware backing
  • Sensitive data leaking into logs, crash reports, clipboard and screenshot snapshots
  • Backup exposure through device sync and platform backup mechanisms

Data in transit

  • TLS configuration, certificate validation and certificate pinning implementation
  • Interception resistance under an active man-in-the-middle position
  • Fallback behaviour when pinning fails or the network is hostile

The API behind the app

Most serious mobile findings are not in the app at all — they are in the API the app talks to, which was built assuming only the app would ever call it. We test authorisation on every endpoint the binary reveals, including endpoints the interface never exercises, because an attacker calls them directly.
 

Manual mobile application penetration testing for native iOS and Android apps: binary analysis, local storage, transport security and the API layer behind the app.


Reference:

https://www.wimd.in/mobile-application-penetration-testing.html



×

×

Tips to earn more points:

  • Get 2 point for each question.
  • Learn more how to earn point quickly with Point Center

Login

×

One more step

Please login to share your idea

Register Login