Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Mobile penetration testing

Posted on 2016-10-28
2
Medium Priority
?
178 Views
Last Modified: 2016-10-28
Hi to all of you,
I've been asked to write guidelines on how to perform Penetration Testin over mobile devices.

Can you please provide me some help , in particular based on your experience the methodology and  tools you use .
Thank you
Carlo
0
Comment
Question by:carlettus
2 Comments
 
LVL 65

Accepted Solution

by:
btan earned 2000 total points
ID: 41863714
You can check out OWASP top ten mobile threats and the pentest scope should include them minimally in scope of appl checks. See checklist in https://www.owasp.org/index.php/OWASP_Mobile_Security_Project

However, for a more comprehensive coverage of Penetration testing, it should include minimally
a) vulnerability scanning that covers network/OS scan and appl scans. The appl scan will cover whitebox check (source code, if avail) and blackbox check (dynamic exchanges with appl). The OWASP can be reference as mentioned earlier
b) manual check for weak spots in the mobile device/architecture/access control/configuration to further intrude so as to surface the potential damage to the whole mobile setup (leading to data breaches). primarily is also to verify the existing safeguards control in place  

Determine the scope of the pentest is important otherwise you need to cover check for the whole robustness of the security architecture, mobile OS (apples/Android/Windows Phone etc) and device hardening and services integrity. This is very different if just going for mobile appl pentest that is driven more from OWASP check as shared earlier. See one PT sharing on iPhone/Android platform.
https://www.owasp.org/images/4/40/Pentesting_Mobile_Applications.pdf

The final report of the mobile security PT should cover the scope, tools, rule of engagement, findings, severity of vulnerability, remediation action and risk acceptance (for findings not closed). have caveats that the testing does not introduce backdoor, bring outage or damage the target or compromise actual target sensitive (personal data) information.
1
 

Author Closing Comment

by:carlettus
ID: 41863720
Thank you , this is an excellent point to start.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

What monsters are hiding in your child's room? In this article I will share with you a tech horror story that could happen to anyone, along with some tips on how you can prevent it from happening to you.
Creating a Cordova application which allow user to save to/load from his Dropbox account the application database.
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question