More MobSF – Mobile Application Penetration Testing #3
Part three of the mobile series works through MobSF output: signer certificates, Android permissions, and the API calls worth following up by hand.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
113 posts
Part three of the mobile series works through MobSF output: signer certificates, Android permissions, and the API calls worth following up by hand.
Read the post →A vulnerability assessment lists what might be wrong. A penetration test proves what an attacker can do with it. The differences, and which one you need.
Read the post →Attackers use models to turn public DNS, GitHub, and job posts into a working map of you. The incident looks sophisticated when the first step was free.
Read the post →Small businesses assume real testing is out of reach. What drives the price of an engagement, and how to get meaningful coverage on a constrained budget.
Read the post →MobSF is the tool you will reach for on every mobile engagement. Installing it, running an APK through it, and what its static analysis actually tells you.
Read the post →Part one of our mobile testing series: jailbreaking, rooting, and getting the IPA or APK you need before any real testing on iOS or Android can start.
Read the post →Credential stuffing is unsophisticated and works anyway, because people reuse passwords. How the attack runs, and which controls actually blunt it.
Read the post →An internal penetration test answers the question an external one cannot: what happens once somebody is already inside. The process, and the usual findings.
Read the post →The Clorox cyberattack cost far more than remediation. Why reputational damage outlasts the incident, and where regular testing changes the outcome.
Read the post →An external penetration test covers everything an attacker can reach from the internet without credentials. What is in scope, and what the results tell you.
Read the post →