This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Mobile Security Project"

From OWASP
Jump to: navigation, search
m (maintenance note tm)
 
(11 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 
=Main=
 
=Main=
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
<div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: lab_big.jpg|link=OWASP_Project_Stages#tab.3DLab_Projects]]</div>
 
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |
Line 10: Line 6:
 
[[File:OWASP_Mobile_Logo_Milan.PNG|center ]]
 
[[File:OWASP_Mobile_Logo_Milan.PNG|center ]]
  
'''[https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10 **New** Mobile Top Ten 2016 - Final Release]'''
+
 
 +
== Maintenance notice ==
 +
 
 +
This site is no longer maintained: please go to https://www2.owasp.org/www-project-mobile-security/ for our new website!
  
  
Line 36: Line 35:
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 +
* [mailto:carlos.holguera@owasp.org Carlos Holguera]
 
|-
 
|-
 
|Mobile Application Security Verification Standard
 
|Mobile Application Security Verification Standard
Line 43: Line 43:
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 +
* [mailto:carlos.holguera@owasp.org Carlos Holguera]
 
|-
 
|-
 
|Mobile Security Checklist
 
|Mobile Security Checklist
Line 50: Line 51:
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:sven.schleier@owasp.org Sven Schleier]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 
* [mailto:jeroen.willemsen@owasp.org Jeroen Willemsen]
 +
* [mailto:carlos.holguera@owasp.org Carlos Holguera]
 
|-
 
|-
 
|iGoat Tool Project
 
|iGoat Tool Project
Line 79: Line 81:
  
 
Not what you are looking for? Please have a look at the '''[https://www.owasp.org/index.php/Mobile_Security_Project_Archive Mobile Security Page Archive]'''  
 
Not what you are looking for? Please have a look at the '''[https://www.owasp.org/index.php/Mobile_Security_Project_Archive Mobile Security Page Archive]'''  
 +
 +
Want to start a new mobile security project? Follow https://www.owasp.org/index.php/Category:OWASP_Project#Starting_a_New_Project or contact one of the leaders of the active projects.
  
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->| valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->| valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
  
== Project details ==
+
== Active OWASP mobile projects ==
 
 
=== Email List ===
 
[[Image:Asvs-bulb.jpg]] [https://groups.google.com/a/owasp.org/forum/#!forum/owasp-mobile-top-10-risks Project Email List]
 
 
 
=== Other active OWASP mobile projects ===
 
 
* [[OWASP Mobile Security Testing Guide|OWASP Mobile Security Testing Guide]]
 
* [[OWASP Mobile Security Testing Guide|OWASP Mobile Security Testing Guide]]
 
* [[OWASP Mobile Security Testing Guide|OWASP Mobile Application Security Verification Standard]]
 
* [[OWASP Mobile Security Testing Guide|OWASP Mobile Application Security Verification Standard]]
Line 94: Line 93:
 
* [[Projects/OWASP Androick Project|AndroidCK project]]
 
* [[Projects/OWASP Androick Project|AndroidCK project]]
 
* [[OWASP SeraphimDroid Project|OWASP SeraphimDroid]]
 
* [[OWASP SeraphimDroid Project|OWASP SeraphimDroid]]
==Project Leaders==
 
{{Template:Contact
 
| name = Jonathan Carter
 
| email = jonathan.carter@owasp.org
 
}}
 
 
{{Template:Contact
 
| name = Milan Singh Thakur
 
| email = milan@owasp.org
 
| username =  Milan Singh Thakur
 
}}
 
  
 
|}
 
|}
Line 110: Line 98:
 
= Top 10 Mobile Risks =
 
= Top 10 Mobile Risks =
  
Please visit the [https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-_Top_Ten_Mobile_Risks project page] for current information.  
+
Please visit the [[OWASP Mobile Top 10|project page]] for current information.  
  
 
== About this list  ==
 
== About this list  ==
Line 254: Line 242:
  
 
== Status note ==
 
== Status note ==
'''Note: Given that the MASVS/MSTG is becoming the leading framework in terms of requirements, we will archive this page and merge requirements with the MASVS, this process is currently taken care of by Abderrahmane AFTAHI. See [https://github.com/OWASP/owasp-masvs/issues/189 the github issue for more details]'''
+
'''Note: Given that the MASVS/MSTG is becoming the leading framework in terms of requirements, we will archive this page and merge requirements with the MASVS, this process is currently taken care of by Abderrahmane AFTAHI (see [https://github.com/OWASP/owasp-masvs/issues/189 the github issue for more details]) and Rocco Gränitz (see [https://github.com/OWASP/owasp-masvs/issues/203 the github issue for more details])'''
  
 
== Mobile Application Coding Guidelines ==
 
== Mobile Application Coding Guidelines ==
Line 397: Line 385:
  
 
[[File:OWASP_Mobile_Top_10_Controls.jpg|center|800px]]
 
[[File:OWASP_Mobile_Top_10_Controls.jpg|center|800px]]
 +
 +
 +
== Status note ==
 +
'''Note: Given that the MASVS/MSTG is becoming the leading framework in terms of requirements, we will archive this page and merge requirements with the MASVS, this process is currently taken care of by Abderrahmane AFTAHI (see [https://github.com/OWASP/owasp-masvs/issues/189 the github issue for more details]) and Rocco Gränitz (see [https://github.com/OWASP/owasp-masvs/issues/203 the github issue for more details])'''
  
 
==Contributors==
 
==Contributors==

Latest revision as of 17:48, 22 October 2019

OWASP Mobile Security Project

OWASP Mobile Logo Milan.PNG


Maintenance notice

This site is no longer maintained: please go to https://www2.owasp.org/www-project-mobile-security/ for our new website!


The OWASP Mobile Security Project is a centralized resource intended to give developers and security teams the resources they need to build and maintain secure mobile applications. Through the project, our goal is to classify mobile security risks and provide developmental controls to reduce their impact or likelihood of exploitation. The project is a breading ground for many different mobile security projects within OWASP. Right now, you can find the following active OWASP mobile security projects:

Project/deliverable More info: Description: Current leaders
Mobile Top Ten Project Page The OWASP Mobile Security top 10 is created to raise awareness for the current mobile security issues.
Mobile Security Testing Guide Project Page A comprehensive manual for mobile app security testing and reverse engineering for iOS and Android mobile security testers as well as developers.
Mobile Application Security Verification Standard Project Page A standard for mobile app security which outlines the security requirements of a mobile application.
Mobile Security Checklist Project Page A checklist which allows easy mapping and scoring of the requirements from the Mobile Application Security Verification Standard based on the Mobile Security Testing Guide.
iGoat Tool Project Project Page A learning tool for iOS developers (iPhone, iPad, etc.). It was inspired by the WebGoat project, and has a similar conceptual flow to it.
Damn Vulnerable iOS Application Project Page An iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment.
Android CK project Project Page A python tool to help in forensics analysis on android.
Seraphimdroid Project Page A privacy and security protection app for Android devices.

Not what you are looking for? Please have a look at the Mobile Security Page Archive

Want to start a new mobile security project? Follow https://www.owasp.org/index.php/Category:OWASP_Project#Starting_a_New_Project or contact one of the leaders of the active projects.

Active OWASP mobile projects