Mobile Hacking: Cheat Sheet
Mobile Hacking: Cheat Sheet
CC BY-SA 4.0 • contact@randorisec.fr • https://www.randorisec.fr The OWASP brand is the property of the OWASP Foundation. OWASP does not endorse any product, services or tools.
Version 0.1 • Updated: 2020-01 Template: https://rstudio.com/resources/cheatsheets/how-to-contribute-a-cheatsheet/ Background psd created by rawpixel.com – https://www.freepik.com
Mobile Hacking CHEAT SHEET
ASSESSING MOBILE APPLICATIONS V0.1
MAIN STEPS OWASP MOBILE SECURITY PROJECTS TOOLS
• Decompile / Disassemble the APK Mobile Security Testing Guide •• adb
adb
• Review the codebase • https://github.com/OWASP/owasp-mstg •• apktool
apktool
• Run the app Mobile Application Security Verification Standard •• jadx
jadx
• Dynamic instrumentation • https://github.com/OWASP/owasp-masvs •• Frida
Frida
• Analyze network communications Mobile Security Checklist •• BurpSuite
BurpSuite
• https://github.com/OWASP/owasp-mstg/tree/master/Checklists
CC BY-SA 4.0 • contact@randorisec.fr • https://www.randorisec.fr The OWASP brand is the property of the OWASP Foundation. OWASP does not endorse any product, services or tools.
Version 0.1 • Updated: 2020-01 Template: https://rstudio.com/resources/cheatsheets/how-to-contribute-a-cheatsheet/ Background psd created by rawpixel.com – https://www.freepik.com