Android App Security: A Structured Approach to Pen Testing

Android App Security: A Structured Approach to Pen Testing

1h 35mAdvanced2019-10-02

Authors

Prashant Pandey

Prashant Pandey

Penetration Tester at Birlasoft

Course details

Android applications are exposed to a variety of security risks that threaten the integrity of your apps and the safety of your end users. In this course, join instructor Prashant Pandey as he shares a structured, comprehensive approach for testing Android apps to uncover some of the most common of these vulnerabilities, demonstrating how to leverage key pen testing tools and frameworks along the way. Prashant starts with the basics, covering the essential aspects of Android pen testing. He then delves into four major tools and frameworks—MobSF, Burp Suite, Android Debug Bridge (adb), and drozer—each catering to one specific aspect of Android app security. Learn how to approach network communication security, static and dynamic application testing, platform integration testing, and more.

Learning objectives
Web vs. Android security
Domains of Android security
Code-level security
Static application testing with MobSF
Dynamic application testing with Burp Suite
Platform interaction testing

Skills covered

Penetration TestingAndroid DevelopmentAndroidMobile DevelopmentGoogleCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Pentesting Android apps
  • What you should know
  • Overview of Android

Android Application Components

  • Activity and services
  • Content providers and receivers

Aspects of Android Security

  • Web vs. Android security
  • Domains of Android security
  • Common terminologies
  • Lab setup

Static Application Testing

  • Introduction to MobSF
  • Setting up MobSF
  • Scanning target applications
  • Manifest analysis
  • Code analysis

Dynamic Application Testing, Part 1

  • Introduction to Burp Suite
  • Burp Suite setup on workstation
  • Burp Suite setup on test device
  • Application testing - Brute force
  • Application testing - Password change

Platform Interaction Testing

  • Introduction to Android Debug Bridge
  • Basic adb commands
  • Testing platform - Insecure logging
  • Testing platform - Insecure data storage

Dynamic Application Testing, Part 2

  • Introduction to drozer
  • drozer architecture
  • drozer setup
  • Sieve application overview
  • Basic commands
  • Activity testing
  • Content provider testing
  • Content provider testing - SQL injection

Conclusion

  • Mobile OWASP Top 10
  • Next steps
40,000 Toman