Mobile Apps Security Testing
@MobileSecurityTesting
2.01K
subscribers
9
files
428
links
Download Telegram
Join
Mobile Apps Security Testing
2.01K subscribers
Mobile Apps Security Testing
https://www.virtuesecurity.com/defeating-android-emulator-detection/
Virtue Security
Defeating Android Emulator Detection
At some point while performing vulnerability assessments on android applications you will encounter apps that don’t want to be run within an emulator. We can’t blame application owners for wanting to ensure that the user interaction they see comes from genuine…
Mobile Apps Security Testing
https://blog.usejournal.com/an-intro-to-pentesting-an-android-phone-464ec4860f39
Medium
Pentesting Android applications by reversing and finding attack surfaces
In this past semester, I was taking a cybersecurity class. Since our awesome professor believe in the concept that we learn by doing and…
Mobile Apps Security Testing
https://jlajara.gitlab.io/posts/2019/05/18/Frida-non-rooted.html
Mobile Apps Security Testing
https://jailbreak.fce365.info/Thread-How-to-use-the-Checkm8-BootROM-Exploit-iPwnDFU-on-iOS-8-up-to-iOS-13-1-1
Mobile Apps Security Testing
https://github.com/axi0mX/ipwndfu
GitHub
GitHub - axi0mX/ipwndfu: open-source jailbreaking tool for many iOS devices
open-source jailbreaking tool for many iOS devices - axi0mX/ipwndfu
Mobile Apps Security Testing
https://blog.ropnop.com/configuring-burp-suite-with-android-nougat/
ropnop blog
Configuring Burp Suite With Android Nougat
Android Nougat changed the default behavior for apps, so installing the Burp CA to user certs no longer works. Here’s two ways to bypass it
Mobile Apps Security Testing
https://anee.me/droidcon-sec-t-ctf-2019-d796be91bb3f
Medium
DroidCon, SEC-T CTF 2019
The ‘Night City’ blackmarket is powered by ‘Droidcoin’. An anonymous crypto-currency. The rogue androids seem to have hacked the ‘Nighty…
Mobile Apps Security Testing
https://vavkamil.cz/2019/09/15/how-to-bypass-android-certificate-pinning-and-intercept-ssl-traffic/
Kamil Vavra @vavkamil
How to bypass Android certificate pinning and intercept SSL traffic
Offensive website security Bug bounty Ethical hacking
Mobile Apps Security Testing
https://bananamafia.dev/post/r2frida-1/
Mobile Apps Security Testing
https://github.com/4ch12dy/xia0FridaScript
GitHub
GitHub - 4ch12dy/FridaLib: iOS/android frida library for reversing
iOS/android frida library for reversing. Contribute to 4ch12dy/FridaLib development by creating an account on GitHub.
Mobile Apps Security Testing
https://twitter.com/aykay/status/1167441682813661189?s=21
Twitter
Andreas Kurtz
I just uploaded a small script to @fridadotre CodeShare to check if keyboard caching is disabled for text inputs in the current view. This allows to dynamically verify @OWASP_MSTG STORAGE‑5 requirement on iOS apps. https://t.co/zy0q19C1zb
Mobile Apps Security Testing
https://twitter.com/linushenze/status/1178657507323060224?s=12
Twitter
Linus Henze
I've created a modified version of checkm8 that doesn't cause your iPhone to crash when loading img4 images (e.g. iBSS): https://t.co/XxSg04RuKH Also includes a signature check removal tool to load unsigned images (currently only supports iPhone 5s, only…
Mobile Apps Security Testing
https://drive.google.com/file/d/1JccmMLi6YTnyRrp_rk6vzKrUX3oXK_Yw/view?usp=drive_open
Mobile Apps Security Testing
https://slides.com/afjoseph/deck/live#/
Slides
Code Execution Analysis in Mobile Apps - Nanosec 2019
A presentation created with Slides.
Mobile Apps Security Testing
https://checkra.in/#release
checkra.in
checkra1n
Jailbreak for iPhone 5s through iPhone X, iOS 12.0 and up
Mobile Apps Security Testing
https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/
Mobile Apps Security Testing
https://twitter.com/maddiestone/status/1202515025879011329?s=12
Twitter
Maddie Stone
🌟
v2 of my free Intro to Android App Reverse Engineering workshop is here!
🌟
I've added 3 new exercises, walk-through videos for all 7 exercises, a new module on obfuscation, & exercises on vuln hunting rather than just malware. I hope it helps! https://t.co/8h2Wjfus1t
Mobile Apps Security Testing
https://github.com/0xmachos/iOS-Security-Guides
GitHub
GitHub - 0xmachos/iOS-Security-Guides: Every iOS security guide
Every iOS security guide . Contribute to 0xmachos/iOS-Security-Guides development by creating an account on GitHub.
Mobile Apps Security Testing
https://github.com/NotSoSecure/android_application_analyzer
GitHub
GitHub - NotSoSecure/android_application_analyzer: The tool is used to analyze the content of the android application in local…
The tool is used to analyze the content of the android application in local storage. - NotSoSecure/android_application_analyzer
Mobile Apps Security Testing
https://blog.nviso.eu/2019/04/02/circumventing-ssl-pinning-in-obfuscated-apps-with-okhttp/
NVISO Labs
Circumventing SSL Pinning in obfuscated apps with OkHttp
TL;DR – There are many Android SSL pinning bypass scripts available for Frida. However, those don’t always work on obfuscated applications. If the application uses OkHttp, there’s…
Mobile Apps Security Testing
https://github.com/m9rco/Genymotion_ARM_Translation/
GitHub
GitHub - m9rco/Genymotion_ARM_Translation:
👾
👾
Genymotion_ARM_Translation Please enjoy!
👾
👾
Genymotion_ARM_Translation Please enjoy!. Contribute to m9rco/Genymotion_ARM_Translation development by creating an account on GitHub.