Skip to content
This repository has been archived by the owner on Nov 14, 2023. It is now read-only.

Latest commit

 

History

History
84 lines (57 loc) · 4.16 KB

File metadata and controls

84 lines (57 loc) · 4.16 KB
layout title type track owasp-project technology status when-day when-time location room-layout description organizers participants invited
blocks/working-session
MSTG Book Sprint - Android Testing Guide
workshop
Mobile Security
true
Mobile
done
Wed
AM-1,PM-1,PM-2,PM-3
Villa-2
unknown
In this book sprint we produce content for the "Android Testing Guide" chapter of the Mobile Security Testing Guide.
Bernhard Mueller,Sven Schleier
Carlos Holguera, Sven Schleier, Jeroen Willemsen
Denis Pilipchuk, Naushad, Bolot Kerimbaev, Marc Rimbau, Alexander Antukh,

owasp mstg

Why

As of today, no widely accepted standard for mobile app security exists. The goal of our project is to rectify this situation. In addition to a mobile appsec security standard, we are producing a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results. We aim to release the guide in the form of a free e-book and potentially a printed book by the end of this year.

What

The objective of this working session is to complete a first draft of the Mobile Security Testing Guide (MSTG). Tasks include:

  • Write original content, such as describing testing processes and writing test cases
  • Proofread and technical edit to improve the overall quality of the MSTG

Participants may join working groups organised along the main topics covered in the guide. Work will be split between working groups based on mobile OS and topics as listed below.

This working session focuses on mobile testing application security on Android.

Associated chapters in the MSTG:

Outcomes

Looking to complete an early release version of the Mobile Security Testing Guide (MSTG) by end of the week.

Synopsis and Takeaways

  • Substantial progress on Encryption Chapter. Finalising Android exception handling for IOS & Android and Integrity testing for IOS

  • QA Process for Android Chapter

  • On target for early access version

  • Looking for sponsorship

How to Join

Follow the "Edit this page here" link at the bottom of this page and add yourself to the "participants" field. Signing up is not mandatory, but helps us to better organize the sessions.

More things to do once you have signed up:

  • Make yourself familiar with the existing content. Or even better, start contributing right away :)
  • Ping us on the OWASP MSTG Slack channel (sushi2k or bernhardm).
  • If you have rooted Android / jailbroken iOS devices, please bring them along to the session.

Who

The target audience for this Working Session is:

  • Developers
  • Security Testers
  • Reverse Engineers
  • Everyone else with good writing skills and some technical know-how :)

Working materials