Owasp mobile testing guide?

45 views
Skip to first unread message

Javi D R

unread,
Jun 8, 2015, 4:36:16 AM6/8/15
to owasp-mobile...@owasp.org
Hi

Is there any testing reference document for native applications similar to the testing guide for Internet? (https://www.owasp.org/index.php/OWASP_Testing_Guide_v4_Table_of_Contents)


Thanks

Jonathan Carter

unread,
Jun 8, 2015, 1:48:23 PM6/8/15
to Javi D R, owasp-mobile...@owasp.org
We're actually in the middle of talks around creating something like this similar to the testing guide for web.

--
You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
For more options, visit https://groups.google.com/a/owasp.org/d/optout.

Javi D R

unread,
Jun 8, 2015, 1:49:25 PM6/8/15
to Jonathan Carter, owasp-mobile...@owasp.org
Beautiful! Thank you for the update

Regards

Jonathan Carter

unread,
Jun 8, 2015, 1:52:28 PM6/8/15
to Javi D R, owasp-mobile...@owasp.org
Just out of curiosity, which platform were you looking for a testing guide for?

Javi D R

unread,
Jun 8, 2015, 1:55:45 PM6/8/15
to Jonathan Carter, owasp-mobile...@owasp.org
Both IOS and Android. I assume testing guide would be similar for both devices (eg - back end validation rules, SSO token, etc...). Of course, there would be specific vulnerabilities for IOS/Android, but the most important tests would be generic

My knowledge is not as advanced as yours, but i would like to help a bit with anything i can. 

Thank you!

Milan Singh Thakur

unread,
Jun 8, 2015, 2:03:32 PM6/8/15
to Javi D R, Jonathan Carter, owasp-mobile...@owasp.org

Hi Javi,

Guide work is in progress. Any new help is always welcome. Till then just keep following testing methodology given on owasp mobile security project site.

Regards
Milan

Yair Amit

unread,
Jun 9, 2015, 4:41:11 AM6/9/15
to Milan Singh Thakur, Javi D R, Jonathan Carter, owasp-mobile...@owasp.org
Hi Milan,

I'd love to contribute to the Guide's work. Who is leading the work on it?

Best regards,
- Yair
Yair Amit
CTO & Co-founder, Skycure

Milan Singh Thakur

unread,
Jun 9, 2015, 4:47:41 AM6/9/15
to Yair Amit, Javi D R, Jonathan Carter, owasp-mobile...@owasp.org
Hi Yair,

Jonathan is leading it along with others from OWASP mobile security
project team.

There is also a scratchpad for it from where the data for guide will
be pulled. Have a look into it and let us know your inputs.

https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-2015_Scratchpad

Regards
Milan

--
Regards,
Milan Singh Thakur

Javi D R

unread,
Jun 9, 2015, 5:34:38 AM6/9/15
to Milan Singh Thakur, Yair Amit, Jonathan Carter, owasp-mobile...@owasp.org
I think i can provide a list of topics to be added here. I will try to send a list today

Javi D R

unread,
Jun 10, 2015, 5:50:49 AM6/10/15
to Milan Singh Thakur, Yair Amit, Jonathan Carter, owasp-mobile...@owasp.org
Hi

This is the list i have by now of things to be tested in mobile devices. Let me know if you find it helpful

Verify that the code is obfuscated
Check that there are lock out mechanisms in place
Try to call a webservice/API without having generated an authentication token
Check that inputs that contain sensitive information don’t remember the information previously entered
Check that once you have logged off in an application, when clicking back you can't navigate to the application again (Android only)
Check that when you are inside the application and  click on back, no sensitive information remains in the forms
Try to setup as password something insecure(password, 1111111…).
Check if you cant access to somebody else data bypassing the front end validations (direct webservice/api call)
Check if you cant execute an operation bypassing authorisation (direct webservice/api call)
Check that after logoff, all data is cleared ( SSO tokens, cookies, etc…)
Check that after session timeout you are automatically logged off
Try to inject any script/sql/html... in the inputs of an application
Try to inject any script/sql/html... directly in the back end call (webservice/api)


Thanks

Milan Singh Thakur

unread,
Jun 10, 2015, 6:28:49 AM6/10/15
to owasp-mobile...@owasp.org, javi.x...@gmail.com, jonatha...@owasp.org, Milan Singh Thakur
Thanks Javi...!!

You inputs are appreciated.We will surely take it into consideration.
Meanwhile, please have a look into Scratchpad for 2015

https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-2015_Scratchpad


Regards,
Milan Singh Thakur
Reply all
Reply to author
Forward
0 new messages