Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Suggestion - Enhancement] Would be better to have OWASP Top 10 tag with the code anaysis which gives good impression. #17

Closed
bugwrangler opened this issue Apr 16, 2015 · 7 comments
Labels
enhancement MobSF enhancements and feature requests

Comments

@bugwrangler
Copy link

No description provided.

@ajinabraham
Copy link
Member

All the vulnerabilities under the following OWASP Mobile Top 10 Mobile, identified via code analysis are detected by the Code Analyser. It's not being categorised under the OWASP Category. Once I am done with the final ruleset for android and iOS, I will prioritise this.

M1: Weak Server Side Controls
M2: Insecure Data Storage
M3: Insufficient Transport Layer Protection
M4: Unintended Data Leakage
M5: Poor Authorization and Authentication
M6: Broken Cryptography
M7: Client Side Injection
M8: Security Decisions Via Untrusted Inputs
M9: Improper Session Handling
M10: Lack of Binary Protections

@ajinabraham ajinabraham added the enhancement MobSF enhancements and feature requests label Apr 17, 2015
@ajinabraham
Copy link
Member

Since OWASP Mobile Top 10 changes, no plans to classify according to ranks, but will add a category tag to appropriate vulns.

@bugwrangler
Copy link
Author

Agreed.

@ajinabraham
Copy link
Member

Difficult to compare between top 10 2014 and 2016
https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10

As the categories themselves are changing between years. This featured won't be added.

@ajinabraham
Copy link
Member

Will be tracking this as an enhancement. We won't be ranking anything but categorising based on OWASP Mobile Top 10 and OWASP MSTG

@ajinabraham
Copy link
Member

Tracked under all enhancements

@ajinabraham
Copy link
Member

Won't be implementing OWASP top 10s changes yearly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement MobSF enhancements and feature requests
Projects
None yet
Development

No branches or pull requests

2 participants