This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Mobile Security Project"

From OWASP
Jump to: navigation, search
(Guide Development Project)
(Undo revision 223879 by Bernhard Mueller (talk))
Line 1,552: Line 1,552:
  
  
=Mobile Security Testing Guide=
+
=Guide Development Project=
 +
==Mobile Application Security Guide Development==
 +
[[File:OWASP_Mobile_Guide_Logo_Milan.PNG]]
  
The Mobile Security Testing Guide (MSTG) contains a comprehensive methodology that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.
+
'''Project initiated by: Milan Singh Thakur'''
  
Refer to the [https://www.owasp.org/index.php/OWASP_Mobile_Security_Testing_Guide#tab=Main Project Page] for details.
+
'''Co-Leaders: Bernhard and Sven'''
 +
 
 +
For more details on this project please check below links:
 +
 
 +
https://groups.google.com/a/owasp.org/forum/#!forum/owasp-mobile-top-10-risks
 +
 
 +
https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-2015_Scratchpad
 +
 
 +
 
 +
The countdown has begun....!!
 +
 
 +
Final Release is going to be Out Soon :)
 +
 
 +
 
 +
Download OWASP-Mobile Security Testing Guide '''BETA''' here
 +
 
 +
https://drive.google.com/file/d/0BxOPagp1jPHWczhwYjRQNzZIekU/view?usp=sharing
 +
 
 +
'''Yes, the most awaited OWASP Mobile Security Guide Final Release is  coming soon.'''
 +
 
 +
 
 +
__NOTOC__ <headertabs />

Revision as of 05:11, 3 December 2016

Lab big.jpg

OWASP Mobile Security Project

OWASP Mobile Logo Milan.PNG


**New** Download OWASP Mobile Apps Checklist 2016 here

**New** Mobile Top Ten 2016 - Candidate Release

Click here to goto Mobile Security Page Archive

The OWASP Mobile Apps Checklist is highly focused on security checks for your mobile apps. If you are a Pentester or an organization which develops mobile apps, then this checklist is what you should consider as BaseLine for your mobile apps..

The OWASP Mobile Security Project is a centralized resource intended to give developers and security teams the resources they need to build and maintain secure mobile applications. Through the project, our goal is to classify mobile security risks and provide developmental controls to reduce their impact or likelihood of exploitation.

Our primary focus is at the application layer. While we take into consideration the underlying mobile platform and carrier inherent risks when threat modeling and building controls, we are targeting the areas that the average developer can make a difference. Additionally, we focus not only on the mobile applications deployed to end user devices, but also on the broader server-side infrastructure which the mobile apps communicate with. We focus heavily on the integration between the mobile application, remote authentication services, and cloud platform-specific features.


We have a Google Doc where anyone who wants to be involved with the project can add their thoughts, suggestions, and take ownership of initiatives - Click here. There are various tasks that people have started over the past 6 months with varying levels of quality and completeness.

This project is still a work in progress. We are small group doing this work and could use more help! If you are interested, please contact one of the project leads or feel free to visit the mailing list as well!

Email List

Asvs-bulb.jpg Project Email List

Project Leaders

Jonathan Carter @
Milan Singh Thakur @

Co-Leaders

Bernhard Mueller @
Sven Schleier @

Former Leaders

Mike Zusman @
Tony DeLaGrange @
Sarath Geethakumar @
Tom Eston @
Don Williams
Jason Haddix @

Top Contributors

Zach Lanier @
Ludovic Petit @
Swapnil Deshmukh @
Beau Woods @
David Martin Aaron @
Luca De Fulgentis @
Andrew Pannell @
Stephanie V @