Главная
Study mode:
on
1
Intro
2
About Derek
3
Why Android?
4
Android OS Split
5
What are the risks?
6
Must Have tools
7
Nice to Have tools
8
Configure your emulator
9
ADB is your friend
10
Find your package file!
11
What about the MANIFEST?
12
More about Drozer
13
App Analysis Guidelines
14
What should be tested?
15
Methodology Overview
16
Static Analysis & App Recon
17
MobSF Dashboard
18
Insecure Communication
19
Insecure Data Storage
20
Extraneous Functionality
21
Embed Malware APK
22
Embedding Malware APK
23
Locate APP Entry Point
24
Re-assemble and sign
25
Way too many steps...
Description:
Dive into the world of Android app security with this 48-minute conference talk from Derbycon 2018, presented by Joff Thyer and Derek Banks. Explore the fundamentals of Android app penetration testing, covering essential topics such as Android OS architecture, potential risks, and must-have tools for testing. Learn how to configure emulators, utilize ADB effectively, and analyze package files and manifests. Gain insights into app analysis guidelines, methodology overviews, and various testing techniques including static analysis, app reconnaissance, and identifying insecure communications and data storage. Discover how to detect extraneous functionality and understand the process of embedding malware in APKs. This comprehensive talk equips security professionals with the knowledge to assess and improve Android app security.

Android App Penetration Testing 101

Add to list
0:00 / 0:00