Главная
Study mode:
on
1
Intro
2
Mobile Powers the World, But Mobile Risk is Pervasive
3
Mobile Security Challenges by the Numbers
4
Web & Mobile are Fundamentally Different
5
Understand the Mobile Attack Surface
6
Understand the Anatomy of a Mobile Attack
7
Get started on the right path
8
Leverage OWASP Mobile Project
9
Use all Your Senses
10
Learn the Mobile Attack Surface
11
Changes in MASVS - Platform Interaction
12
Sensitive data leaks like an overfilled drink
13
Changes in MASVS - Data Storage
14
Don't cringe at client-side security controls
15
Test network on mobile
16
Don't water down auth & session mgmt
17
The order matters: Test first, then resilience
18
Framework for Setting Policy
19
Don't mix up Security & Privacy, Not the Same
20
The flavor palate varies widely
21
Buy a dev a drink, and they might buy you one too
22
Tony's Mobile Top Ten Recipe
23
Summary Recommendations
24
A Sampling of OSS Tools
25
Leverage Mobile AppSec Testing Checklist
26
Build Security Into Your SDLC
Description:
Explore the latest OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG) specifications in this 44-minute conference talk. Dive into the pervasive nature of mobile risk and the unique security challenges posed by mobile platforms. Learn how to effectively leverage OWASP mobile projects, understand the mobile attack surface, and navigate changes in platform interaction and data storage. Discover best practices for testing network security, authentication, and session management on mobile devices. Gain insights into setting security policies, distinguishing between security and privacy concerns, and integrating security into your software development lifecycle. Explore a curated list of open-source tools and utilize the Mobile AppSec Testing Checklist to enhance your mobile application security testing approach.

How the Latest MASVS and MSTG Specs Enhance Mobile Penetration Testing

OWASP Foundation
Add to list