Skip to main content

pentest-mobile-app

OWASP Mobile Top 10 security testing for Android and iOS — local storage, certificate pinning bypass, IPC abuse, and binary protections.

소스 정보

저장소
jd-opensource/JoySafeter
최근 소스 활동
2026년 2월 11일 09:17
감지된 SKILL.md 언어
영어
스타
312
포크
58

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
3 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
pentest-mobile-app
description
OWASP Mobile Top 10 security testing for Android and iOS — local storage, certificate pinning bypass, IPC abuse, and binary protections.
# Pentest Mobile App ## Purpose Mobile apps are completely absent from Shannon (web-only) and all existing skills. Mobile apps often share backend APIs but introduce unique attack surfaces: local storage, pinning, intent handling, binary protections. ## Prerequisites ### Authorization Requirements - **Written authorization** with mobile app testing scope - **APK/IPA files** or access to app store downloads - **Test devices** or emulators (rooted Android, jailbroken iOS preferred) - **Backend API documentation** if available ### Environment Setup - Frida for runtime instrumentation - Objection for quick mobile security testing - MobSF for automated static/dynamic analysis - jadx for Android decompilation, Hopper for iOS - Burp Suite configured as mobile proxy ## Core Workflow 1. **Static Analysis**: Decompile APK/IPA, analyze for hardcoded secrets, insecure storage patterns, weak crypto, exported components, debug flags. 2. **Insecure Data Storage**: Check SharedPreferences/Keychain for sensitive data, SQLite DBs, log files, clipboard exposure, backup extraction. 3. **Certificate Pinning Bypass**: Use Frida/Objection to disable pinning, intercept HTTPS traffic, test HTTP fallback. 4. **Auth & Session on Mobile**: Token storage security, biometric bypass, session timeout, deep link auth bypass. 5. **IPC Testing**: Exported Activities/Services/BroadcastReceivers (Android), URL scheme hijacking (iOS), intent injection, custom URI handler abuse. 6. **Binary Protections**: Root/jailbreak detection bypass, anti-tampering bypass, code obfuscation assessment, runtime manipulation via Frida. 7. **Mobile-Context API Testing**: APIs trusting mobile client-side validation, device-ID spoofing, push notification token abuse. ## Tool Categories | Category | Tools | Purpose | |----------|-------|---------| | Runtime Instrumentation | Frida, Objection | Hook functions, bypass protections | | Static Analysis | MobSF, jadx, Hopper | Decompile and analyze binaries | | Traffic Interception | Burp Suite, mitmproxy | HTTPS interception with pinning bypass | | Android Testing | adb, drozer | Component testing, IPC analysis | | iOS Testing | Objection, cycript | Runtime manipulation, keychain dump | ## References - `references/tools.md` - Tool function signatures and parameters - `references/workflows.md` - Attack pattern definitions and test vectors
GitHub에서 보기