Mobile Apps Security Testing
@MobileSecurityTesting
2.01K
subscribers
9
files
428
links
Download Telegram
Join
Mobile Apps Security Testing
2.01K subscribers
Mobile Apps Security Testing
https://anee.me/droidcon-sec-t-ctf-2019-d796be91bb3f
Medium
DroidCon, SEC-T CTF 2019
The ‘Night City’ blackmarket is powered by ‘Droidcoin’. An anonymous crypto-currency. The rogue androids seem to have hacked the ‘Nighty…
Mobile Apps Security Testing
https://vavkamil.cz/2019/09/15/how-to-bypass-android-certificate-pinning-and-intercept-ssl-traffic/
Kamil Vavra @vavkamil
How to bypass Android certificate pinning and intercept SSL traffic
Offensive website security Bug bounty Ethical hacking
Mobile Apps Security Testing
https://bananamafia.dev/post/r2frida-1/
Mobile Apps Security Testing
https://github.com/4ch12dy/xia0FridaScript
GitHub
GitHub - 4ch12dy/FridaLib: iOS/android frida library for reversing
iOS/android frida library for reversing. Contribute to 4ch12dy/FridaLib development by creating an account on GitHub.
Mobile Apps Security Testing
https://twitter.com/aykay/status/1167441682813661189?s=21
Twitter
Andreas Kurtz
I just uploaded a small script to @fridadotre CodeShare to check if keyboard caching is disabled for text inputs in the current view. This allows to dynamically verify @OWASP_MSTG STORAGE‑5 requirement on iOS apps. https://t.co/zy0q19C1zb
Mobile Apps Security Testing
https://twitter.com/linushenze/status/1178657507323060224?s=12
Twitter
Linus Henze
I've created a modified version of checkm8 that doesn't cause your iPhone to crash when loading img4 images (e.g. iBSS): https://t.co/XxSg04RuKH Also includes a signature check removal tool to load unsigned images (currently only supports iPhone 5s, only…
Mobile Apps Security Testing
https://drive.google.com/file/d/1JccmMLi6YTnyRrp_rk6vzKrUX3oXK_Yw/view?usp=drive_open
Mobile Apps Security Testing
https://slides.com/afjoseph/deck/live#/
Slides
Code Execution Analysis in Mobile Apps - Nanosec 2019
A presentation created with Slides.
Mobile Apps Security Testing
https://checkra.in/#release
checkra.in
checkra1n
Jailbreak for iPhone 5s through iPhone X, iOS 12.0 and up
Mobile Apps Security Testing
https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/
Mobile Apps Security Testing
https://twitter.com/maddiestone/status/1202515025879011329?s=12
Twitter
Maddie Stone
🌟
v2 of my free Intro to Android App Reverse Engineering workshop is here!
🌟
I've added 3 new exercises, walk-through videos for all 7 exercises, a new module on obfuscation, & exercises on vuln hunting rather than just malware. I hope it helps! https://t.co/8h2Wjfus1t
Mobile Apps Security Testing
https://github.com/0xmachos/iOS-Security-Guides
GitHub
GitHub - 0xmachos/iOS-Security-Guides: Every iOS security guide
Every iOS security guide . Contribute to 0xmachos/iOS-Security-Guides development by creating an account on GitHub.
Mobile Apps Security Testing
https://github.com/NotSoSecure/android_application_analyzer
GitHub
GitHub - NotSoSecure/android_application_analyzer: The tool is used to analyze the content of the android application in local…
The tool is used to analyze the content of the android application in local storage. - NotSoSecure/android_application_analyzer
Mobile Apps Security Testing
https://blog.nviso.eu/2019/04/02/circumventing-ssl-pinning-in-obfuscated-apps-with-okhttp/
NVISO Labs
Circumventing SSL Pinning in obfuscated apps with OkHttp
TL;DR – There are many Android SSL pinning bypass scripts available for Frida. However, those don’t always work on obfuscated applications. If the application uses OkHttp, there’s…
Mobile Apps Security Testing
https://github.com/m9rco/Genymotion_ARM_Translation/
GitHub
GitHub - m9rco/Genymotion_ARM_Translation:
👾
👾
Genymotion_ARM_Translation Please enjoy!
👾
👾
Genymotion_ARM_Translation Please enjoy!. Contribute to m9rco/Genymotion_ARM_Translation development by creating an account on GitHub.
Mobile Apps Security Testing
https://zeroinformationsecurity.wordpress.com/2020/05/07/the-only-way-to-bypass-ssl-pinning-on-ios-13
ZeroInfoSec - James Guthrie
The Only Way to Bypass SSL Pinning on iOS 13 - ZeroInfoSec
Use Frida and Objection! By now you should know how to install Burp Suite and set it up to proxy your iOS device. If this is all you do then you will come up against TLS errors. You have to use Frida and Objection to inject an SSL bypass into the app you're…
Mobile Apps Security Testing
https://blog.nviso.eu/2020/06/12/intercepting-flutter-traffic-on-ios/
NVISO Labs
Intercepting Flutter traffic on iOS
My previous blogposts explained how to intercept Flutter traffic on Android ARMv8, with a detailed follow along guide for ARMv7. This blogpost does the same for iOS.
⚠️
Update August 2022
⚠️
An upda…
Mobile Apps Security Testing
https://github.com/NVISO-BE/MagiskTrustUserCerts
GitHub
GitHub - NVISOsecurity/AlwaysTrustUserCerts: A Magisk/KernelSU module that automatically adds user certificates to the system root…
A Magisk/KernelSU module that automatically adds user certificates to the system root CA store - NVISOsecurity/AlwaysTrustUserCerts
Mobile Apps Security Testing
https://blog.nviso.eu/2017/12/22/intercepting-https-traffic-from-apps-on-android-7-using-magisk-burp/
NVISO Labs
Intercepting HTTPS Traffic from Apps on Android 7+ using Magisk & Burp
Intercepting HTTPS traffic is a necessity with any mobile security assessment. By adding a custom CA to Android, this can easily be done. As of Android Nougat, however, apps don’t trust clien…
Mobile Apps Security Testing
https://github.com/ElderDrivers/EdXposed/
GitHub
GitHub - ElderDrivers/EdXposed: Elder driver Xposed Framework.
Elder driver Xposed Framework. Contribute to ElderDrivers/EdXposed development by creating an account on GitHub.
Mobile Apps Security Testing
https://mobexler.com/checklist.htm