Android App Security: A Structured Approach to Pen Testing
1h 35mAdvanced2019-10-02
Authors

Prashant Pandey
Penetration Tester at Birlasoft
Course details
Android applications are exposed to a variety of security risks that threaten the integrity of your apps and the safety of your end users. In this course, join instructor Prashant Pandey as he shares a structured, comprehensive approach for testing Android apps to uncover some of the most common of these vulnerabilities, demonstrating how to leverage key pen testing tools and frameworks along the way. Prashant starts with the basics, covering the essential aspects of Android pen testing. He then delves into four major tools and frameworks—MobSF, Burp Suite, Android Debug Bridge (adb), and drozer—each catering to one specific aspect of Android app security. Learn how to approach network communication security, static and dynamic application testing, platform integration testing, and more.
Learning objectives
Web vs. Android security
Domains of Android security
Code-level security
Static application testing with MobSF
Dynamic application testing with Burp Suite
Platform interaction testing
Learning objectives
Web vs. Android security
Domains of Android security
Code-level security
Static application testing with MobSF
Dynamic application testing with Burp Suite
Platform interaction testing
Skills covered
Penetration TestingAndroid DevelopmentAndroidMobile DevelopmentGoogleCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Pentesting Android apps
- 02 - What you should know
- 03 - Overview of Android
1. Android Application Components
- 04 - Activity and services
- 05 - Content providers and receivers
2. Aspects of Android Security
- 06 - Web vs. Android security
- 07 - Domains of Android security
- 08 - Common terminologies
- 09 - Lab setup
3. Static Application Testing
- 10 - Introduction to MobSF
- 11 - Setting up MobSF
- 12 - Scanning target applications
- 13 - Manifest analysis
- 14 - Code analysis
4. Dynamic Application Testing, Part 1
- 15 - Introduction to Burp Suite
- 16 - Burp Suite setup on workstation
- 17 - Burp Suite setup on test device
- 18 - Application testing - Brute force
- 19 - Application testing - Password change
5. Platform Interaction Testing
- 20 - Introduction to Android Debug Bridge
- 21 - Basic adb commands
- 22 - Testing platform - Insecure logging
- 23 - Testing platform - Insecure data storage
6. Dynamic Application Testing, Part 2
- 24 - Introduction to drozer
- 25 - drozer architecture
- 26 - drozer setup
- 27 - Sieve application overview
- 28 - Basic commands
- 29 - Activity testing
- 30 - Content provider testing
- 31 - Content provider testing - SQL injection
Conclusion
- 32 - Mobile OWASP Top 10
- 33 - Next steps