owasp-mstg
theos-jailed
Our great sponsors
owasp-mstg | theos-jailed | |
---|---|---|
1 | 7 | |
0 | 339 | |
- | - | |
10.0 | 3.6 | |
almost 2 years ago | 4 months ago | |
Shell | ||
Creative Commons Attribution Share Alike 4.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
owasp-mstg
-
Google Play rolls out an "Independent security review" badge for apps
I found a more detailed explanation of it: https://github.com/julepka/owasp-mstg/blob/master/Document/0...
> Generally, you should provide compiled code with as little explanation as possible. Some metadata, such as debugging information, line numbers, and descriptive function or method names, make the binary or bytecode easier for the reverse engineer to understand, but these aren't needed in a release build and can therefore be safely omitted without impacting the app's functionality.
I'm not a big fan of the reasoning, as it's security through obscurity. Which is not the worst tradeoff, but these days it just makes public bug bounties (and other public auditing) end up being less of an interesting prospect for improving security.
theos-jailed
-
[Tutorial] Fix Apollo with personal API key and FLEX 3
There's tools that can do that for you. Theos-jailed (https://github.com/kabiroberai/theos-jailed), Sideloadly (https://sideloadly.io), and Azule (https://github.com/Al4ise/Azule) are probably the most user-friendly ways to do it.
-
Is it possible to inject an Orion tweak into an ipa and have it work on a jailed device
I’d give Theos-Jailed a try. Seems like some people (at least in the past) got it to work.
-
[Question] Can anyone make a tutorial on how to "compile" a tweak to an ipa?
Here you go: https://github.com/kabiroberai/theos-jailed
- [question] how do I view contents of a decrypted ipa file in windows 11?
-
[Free Release] Azule - Jailed Tweaks made Simple
The 2 widely-used tools for bringing tweaks to jailed devices are kabiroberai's theos jailed and Brandon Plank's iPAPatcher. Both tools, though, have their own issues.
-
[Question] Does anyone know how to import .dylib files as frameworks (for example Rocket.dylib from Rocket for Instagram) using theos jailed, provided that I don’t have the source code and therefore don’t have the .h files?
check out theos-jailed, that’s how tweaked IPAs are usually made.
-
Does Supercharge support importing .dylib files as frameworks?
It does! You can add dylib files from the Libraries section of the editor and supporting files to Resources (after which you may also need to hook the framework’s code to change where it looks for the support files). Following that, you may need to hook the dylib’s methods that fetch resources in order to point them to the right folder. Note that I also have a detailed explanation of how to do something similar in Theos Jailed’s docs: see https://github.com/kabiroberai/theos-jailed/wiki/Usage#injecting-a-cydia-tweak. Good luck :)
What are some alternatives?
buildAPKs - Really quickly build APKs on handheld device (smartphone or tablet) in Amazon, Android, Chromebook and Windows📲 See https://buildapks.github.io/docsBuildAPKs/setup to start building APKs.
Azule
android-udev-rules - Android udev rules list aimed to be the most comprehensive on the net
MonkeyDev - CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.
website - The elementary.io website
Kaitai Struct - Kaitai Struct: declarative language to generate binary data parsers in C++ / C# / Go / Java / JavaScript / Lua / Nim / Perl / PHP / Python / Ruby
reFlutter - Flutter Reverse Engineering Framework
Cronet.framework - This package makes it easy to use Chromium's networking stack in your iOS applications
owasp-masvs - The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
Apollo-CustomApiCredentials - Tweak to use your own reddit API credentials in Apollo
owasp-mastg - The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).