owasp-mstg
buildAPKs
Our great sponsors
owasp-mstg | buildAPKs | |
---|---|---|
1 | 1 | |
0 | 328 | |
- | - | |
10.0 | 1.8 | |
over 1 year ago | about 2 years ago | |
Shell | ||
Creative Commons Attribution Share Alike 4.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-mstg
-
Google Play rolls out an "Independent security review" badge for apps
I found a more detailed explanation of it: https://github.com/julepka/owasp-mstg/blob/master/Document/0...
> Generally, you should provide compiled code with as little explanation as possible. Some metadata, such as debugging information, line numbers, and descriptive function or method names, make the binary or bytecode easier for the reverse engineer to understand, but these aren't needed in a release build and can therefore be safely omitted without impacting the app's functionality.
I'm not a big fan of the reasoning, as it's security through obscurity. Which is not the worst tradeoff, but these days it just makes public bug bounties (and other public auditing) end up being less of an interesting prospect for improving security.
buildAPKs
We haven't tracked posts mentioning buildAPKs yet.
Tracking mentions began in Dec 2020.
What are some alternatives?
android-foss - A list of Free and Open Source Software (FOSS) for Android – saving Freedom and Privacy.
TermuxArch - You can use setupTermuxArch.bash 📲 to install Arch Linux in Amazon, Android, Chromebook and Windows. https://sdrausty.github.io/TermuxArch/docs/install
owasp-mastg - The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
ReverseAPK - Quickly analyze and reverse engineer Android packages
termux-archlinux - You can use setupTermuxArch.bash 📲 to install Arch Linux in Termux on Amazon, Android, Chromebook and Windows. https://sdrausty.github.io/termux-archlinux/
buildAPKs - Really quickly build APKs on handheld device (smartphone and tablet) in Amazon, Android, Chromebook, PRoot and Windows📲 See https://buildapks.github.io/docsBuildAPKs/setup to start building APKs.
CrAnberry - Rooting the ChromeOS Android Subsystem post v77
reFlutter - Flutter Reverse Engineering Framework
transmission-android - Transmission daemon for android. Single APK with external settings.
android-udev-rules - Android udev rules list aimed to be the most comprehensive on the net
website - The elementary.io website
Androl4b - A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis