owasp-masvs
owasp-mastg
Our great sponsors
owasp-masvs | owasp-mastg | |
---|---|---|
10 | 22 | |
1,942 | 11,272 | |
1.7% | 1.4% | |
4.3 | 8.3 | |
4 days ago | 8 days ago | |
Python | Python | |
GNU General Public License v3.0 or later | Creative Commons Attribution Share Alike 4.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-masvs
-
More ways to identify independently security tested apps on Google Play
https://github.com/OWASP/owasp-masvs :
> The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
- OWASP MASVS v2.0.0 is out!
-
How can we get our Apps validated against OWASP's MASVS and does it shown on the PlayStore?
owasp-masvs
-
What security measures should one keep in mind when developing a fin-tech app ?
There is an organization called OWASP that has a series of guidelines, one of which concerns itself with mobile app security. When I worked for a fintech startup, audits were executed based on this guideline, so maybe it's worth taking a look at it: https://github.com/OWASP/owasp-masvs
-
What's your favorite cybersecurity documentation and why?
OWASP MASVS, MSTG, and WSTG.
-
Critical Security Areas That Software Engineers Have To Know To Secure Their Solutions
Security falls under the category non-functional requirements. It should define the needed security functionality the software has to satisfy. To save up time and not re-invent the wheel on each new project, you can select security requirements from a catalog. There is a general one called "Application Security Verification Standard (ASVS)" and one for the mobile named "Mobile Application Verification Standard (MASVS)". They contain a collection of requirements which are best practices for each listed category. Fortunately they have mapped those requirements with CWE (common weakness enumeration which is basically a list of software and hardware weaknesses). Depending on the used tools, those CWEs can be automatically scanned in your code.
-
Refactoring of Mobile Application Security Verification Standard (Masvs)
The project team of the OWASP Mobile Application Security Verification Standard (https://github.com/OWASP/owasp-masvs) is right in the middle of completely refactoring the document and it's requirements for mobile apps! We were re-visiting this topic in the last few months and tried to identify the current pain points and how they could be removed.
In order to move forward we are looking for your feedback! If you would like to share any feedback or comments of what should be changed in the MASVS, please do so by participating in our Github Discussion:
https://github.com/OWASP/owasp-masvs/discussions/553
-
Is there a point to logging out of apps?
I've only been able to scan through the MASVS L2 standard info which you sent. I'll review it more later.
owasp-mastg
- More ways to identify independently security tested apps on Google Play
-
Google Play rolls out an "Independent security review" badge for apps
https://mas.owasp.org/ :
> The OWASP Mobile Application Security (MAS) flagship project provides a security standard for mobile apps (OWASP MASVS) and a comprehensive testing guide (OWASP MASTG) that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases
- Need Help on Patching
- The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
- Mobile game security - how to?
-
Are android bugs mostly api and web ?
Have a look at the OWASP Mobile Application Testing Guide https://github.com/OWASP/owasp-mastg
-
How can we get our Apps validated against OWASP's MASVS and does it shown on the PlayStore?
owasp-mastg
-
How do you check your app for security issues?
Be aware that this kind of tools shouldn't be seen as a substitute for a manual and thorough pentesting of the application. As u/StoryOfDavid suggested decompiling the application (I usually use jadx for this) and using Wireshark to check the network traffic are good ways to start assessing the security of your application. If you want to be thorough I suggest going through the OWASP-MSTG guide (now renamed to MASTG) which provides a categorization of possible security issues, with a description of the problem and actionable ways to statically/dynamically analyze your application.
-
Securing API keys, clientId, clientSecret etc while distributing to App Store? Ways to prevent reverse engineering?
Check out OWASP, they have plenty documentation about threat modeling and attack vectors for mobile apps. Regarding jailbreak detection, see the following: https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06j-Testing-Resiliency-Against-Reverse-Engineering.md
-
Moving from Web application pentesting to mobile.
- OWASP is as usual a good resource: https://owasp.org/www-project-mobile-security-testing-guide/
What are some alternatives?
pwndoc - Pentest Report Generator
H4CKINTO - H4CKINTO - Remote Android Management Suite
wstg - The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
grapefruit - (WIP) Runtime Application Instruments for iOS. Previously Passionfruit
ASVS - Application Security Verification Standard
linux-smart-enumeration - Linux enumeration tool for pentesting and CTFs with verbosity levels
lightnovel-crawler - Generate and download e-books from online sources.
hacktricks - Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
Aion-Japanese-Voice-Pack - Change the voice acting of your Aion client into sweet Japanese or Korean.
audiohq_module - Provide binary and apk for controlling each applications volume using Magisk
milewski-ctfp-pdf - Bartosz Milewski's 'Category Theory for Programmers' unofficial PDF and LaTeX source
buildAPKs - Really quickly build APKs on handheld device (smartphone or tablet) in Amazon, Android, Chromebook and Windows📲 See https://buildapks.github.io/docsBuildAPKs/setup to start building APKs.