owasp-mstg
hacktricks
owasp-mstg | hacktricks | |
---|---|---|
1 | 6 | |
2 | 10,272 | |
- | 1.6% | |
10.0 | 9.6 | |
about 3 years ago | 3 days ago | |
JavaScript | ||
Creative Commons Attribution Share Alike 4.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-mstg
-
Google Play rolls out an "Independent security review" badge for apps
I found a more detailed explanation of it: https://github.com/julepka/owasp-mstg/blob/master/Document/0...
> Generally, you should provide compiled code with as little explanation as possible. Some metadata, such as debugging information, line numbers, and descriptive function or method names, make the binary or bytecode easier for the reverse engineer to understand, but these aren't needed in a release build and can therefore be safely omitted without impacting the app's functionality.
I'm not a big fan of the reasoning, as it's security through obscurity. Which is not the worst tradeoff, but these days it just makes public bug bounties (and other public auditing) end up being less of an interesting prospect for improving security.
hacktricks
- Where do you look for help when doing ctf
-
Desktop background changed suddenly
Honestly when I saw desktopimgdownldr.exe I thought LOLBAS as well. https://github.com/carlospolop/hacktricks/blob/master/windows-hardening/basic-cmd-for-pentesters.md
- Best way to learn advanced DOM XSS.
-
Trying to find a username and password to access a virtual machine to solve a CTF?
shot in the dark.... but the port 135 being open might be interesting?
- An Effective Pentesting Methodology
- Comprehensive Guide to Pen-Testing
What are some alternatives?
theos-jailed - A Theos module to develop jailed tweaks for iOS 8 and up
dirsearch - Web path scanner
reFlutter - Flutter Reverse Engineering Framework
mastg - The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
QuantumPuzzleGenerator - Puzzle game for Android and iOS, written in F#
DumpsterFire - "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.