?
Solved

Mobile penetration testing

Posted on 2016-10-28
2
Medium Priority
?
166 Views
Last Modified: 2016-10-28
Hi to all of you,
I've been asked to write guidelines on how to perform Penetration Testin over mobile devices.

Can you please provide me some help , in particular based on your experience the methodology and  tools you use .
Thank you
Carlo
0
Comment
Question by:carlettus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 64

Accepted Solution

by:
btan earned 2000 total points
ID: 41863714
You can check out OWASP top ten mobile threats and the pentest scope should include them minimally in scope of appl checks. See checklist in https://www.owasp.org/index.php/OWASP_Mobile_Security_Project

However, for a more comprehensive coverage of Penetration testing, it should include minimally
a) vulnerability scanning that covers network/OS scan and appl scans. The appl scan will cover whitebox check (source code, if avail) and blackbox check (dynamic exchanges with appl). The OWASP can be reference as mentioned earlier
b) manual check for weak spots in the mobile device/architecture/access control/configuration to further intrude so as to surface the potential damage to the whole mobile setup (leading to data breaches). primarily is also to verify the existing safeguards control in place  

Determine the scope of the pentest is important otherwise you need to cover check for the whole robustness of the security architecture, mobile OS (apples/Android/Windows Phone etc) and device hardening and services integrity. This is very different if just going for mobile appl pentest that is driven more from OWASP check as shared earlier. See one PT sharing on iPhone/Android platform.
https://www.owasp.org/images/4/40/Pentesting_Mobile_Applications.pdf

The final report of the mobile security PT should cover the scope, tools, rule of engagement, findings, severity of vulnerability, remediation action and risk acceptance (for findings not closed). have caveats that the testing does not introduce backdoor, bring outage or damage the target or compromise actual target sensitive (personal data) information.
1
 

Author Closing Comment

by:carlettus
ID: 41863720
Thank you , this is an excellent point to start.
0

Featured Post

10 Questions to Ask when Buying Backup Software

Choosing the right backup solution for your organization can be a daunting task. To make the selection process easier, ask solution providers these 10 key questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question