Web and Mobile Application Fuzzing Best Practices
Most testers fuzz badly: wrong wordlists, wrong extensions, no attention to responses. Our rules for fuzzing properly, plus a custom tool to get started.
Read the post →Android and iOS application testing: local data storage, certificate handling, reverse engineering resistance, and the backend APIs behind the app.
9 posts
Most testers fuzz badly: wrong wordlists, wrong extensions, no attention to responses. Our rules for fuzzing properly, plus a custom tool to get started.
Read the post →Mobile apps write more to the log than their developers think. Reading iOS and Android logs to find the sensitive data an app leaks without meaning to.
Read the post →Part five of the mobile series sets up Android Studio and an emulator for testing, including the device configuration that makes traffic interception work.
Read the post →The last of our MobSF coverage: browsable activities, network security config, certificate analysis, and where the automated report stops being useful.
Read the post →Part three of the mobile series works through MobSF output: signer certificates, Android permissions, and the API calls worth following up by hand.
Read the post →MobSF is the tool you will reach for on every mobile engagement. Installing it, running an APK through it, and what its static analysis actually tells you.
Read the post →Part one of our mobile testing series: jailbreaking, rooting, and getting the IPA or APK you need before any real testing on iOS or Android can start.
Read the post →Certificate pinning and root detection raise the cost of attacking a mobile app. They do not make it unhackable, and here is how testers get past both.
Read the post →OWASP’s MASTG is the closest thing mobile testing has to a standard. What the checklist covers, and where a penetration test goes beyond ticking it off.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.