owasp-mastg
website
owasp-mastg | website | |
---|---|---|
22 | 186 | |
11,290 | 1,229 | |
0.7% | 0.2% | |
8.3 | 9.5 | |
about 8 hours ago | 8 days ago | |
Python | PHP | |
Creative Commons Attribution Share Alike 4.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-mastg
- More ways to identify independently security tested apps on Google Play
-
Google Play rolls out an "Independent security review" badge for apps
https://mas.owasp.org/ :
> The OWASP Mobile Application Security (MAS) flagship project provides a security standard for mobile apps (OWASP MASVS) and a comprehensive testing guide (OWASP MASTG) that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases
- Need Help on Patching
- The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
- Mobile game security - how to?
-
Are android bugs mostly api and web ?
Have a look at the OWASP Mobile Application Testing Guide https://github.com/OWASP/owasp-mastg
-
How can we get our Apps validated against OWASP's MASVS and does it shown on the PlayStore?
owasp-mastg
-
How do you check your app for security issues?
Be aware that this kind of tools shouldn't be seen as a substitute for a manual and thorough pentesting of the application. As u/StoryOfDavid suggested decompiling the application (I usually use jadx for this) and using Wireshark to check the network traffic are good ways to start assessing the security of your application. If you want to be thorough I suggest going through the OWASP-MSTG guide (now renamed to MASTG) which provides a categorization of possible security issues, with a description of the problem and actionable ways to statically/dynamically analyze your application.
-
Securing API keys, clientId, clientSecret etc while distributing to App Store? Ways to prevent reverse engineering?
Check out OWASP, they have plenty documentation about threat modeling and attack vectors for mobile apps. Regarding jailbreak detection, see the following: https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06j-Testing-Resiliency-Against-Reverse-Engineering.md
-
Moving from Web application pentesting to mobile.
- OWASP is as usual a good resource: https://owasp.org/www-project-mobile-security-testing-guide/
website
-
Microsoft Edge ignores user wishes, slurps tabs from Chrome without permission
I hear you, but they've all moved along in leaps and bounds. Some options if you ever look again -
* ElementaryOS(https://elementary.io/)
-
Linux distributions for beginners in 2024: Expert tested and reviewed
I’ve seen Raycast adjacent apps for Linux, but I don’t know what the current go-to all the kids are using these days. I used Quicksilver on OS X back in the day, which kind of defined the category I think. But these days I try to keep it simple.
Elementary OS seems to be trying to solve for the design issue, but it’s not as polished as macOS and there are still all the 3rd party apps to contend with. I’ve tried it, and it didn’t have me considering a full time switch.
https://elementary.io/
For me, one of the big things keeping me on macOS is the sync between devices. 20 years ago it seemed much easier to move to Linux, because I didn’t have to worry about my contacts, calendar, etc being in sync everywhere. Having all that stuff, and the handoff between devices, just work is a huge benefit. There are probably ways to sync various things between iOS and Linux, but then researching all the options, setting it up, and keeping up on it all, becomes a hobby. That’s not a hobby I want at this stage of my life.
- Do you think Pop!_OS should be re-named to "Cosmic" when the new DE comes out?
-
Linux Lite: Easy to Use Free Linux Operating System
I thought ElementaryOS was dead due to infighting between the two cofounders, but it still seems to be going: https://elementary.io/
(I installed it on one box a few years ago and liked it, but moved back to Ubuntu once I learned about its conflict in the team.)
-
Recommend me a distro for my stepdad
As an alternative to the other (great) suggestions, check out ElementaryOS.
-
How many of you are still using mullvad?
But get an old laptop, download and install on it https://elementary.io/, or PopOS or Debian (they all resemble macOS) or whatever distro you like the most. And start tinkering.
-
Package management
I would suggest installing elementaryOS inside a VM, and follow their getting started guide
-
Recomandare Linux Distro pentru un incepator?
Elementary OS e un distro de Linux cu aspect de macos
-
Old laptop,need help with an os.
Maybe take a look at https://elementary.io/? It was one of the better "out of the box" linux distros when I was last using linux.
-
Egg⛩️🐧irl
It warms my heart seeing all my fellow linux users here! 😊 I personally use elementary OS because the desktop is pretty 🥺. Also, the lead of the project is a trans woman!
What are some alternatives?
H4CKINTO - H4CKINTO - Remote Android Management Suite
WhyNotWin11 - Detection Script to help identify why your PC is not Windows 11 Release Ready. Now Supporting Update Checks!
owasp-masvs - The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
pop - A project for managing all Pop!_OS sources
grapefruit - (WIP) Runtime Application Instruments for iOS. Previously Passionfruit
void-packages - The Void source packages collection
linux-smart-enumeration - Linux enumeration tool for pentesting and CTFs with verbosity levels
krohnkite - A dynamic tiling extension for KWin
hacktricks - Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
egpu-switcher - 🖥🐧 Setup script for eGPUs in Linux (X.Org)
audiohq_module - Provide binary and apk for controlling each applications volume using Magisk
markdown-preview.vim - ⚠️ PLEASE USE https://github.com/iamcco/markdown-preview.nvim INSTEAD