This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Mobile Security Testing Guide"

From OWASP
Jump to: navigation, search
(Preview Release)
(Contributors)
Line 274: Line 274:
 
= Acknowledgements =
 
= Acknowledgements =
  
==Contributors==
+
== Acknowledgments ==
  
The Mobile Security Testing Guide was initiated by  [https://www.owasp.org/index.php/User:Milan_Singh_Thakur Milan Singh Thakur] in 2015. The original document was hosted on Google Drive. Guide development was moved to GitHub in October 2016. Below is the full list of contributors for each revision.
+
=== Authors ===
  
=== MSTG in its current form ===
+
====Bernhard Mueller ====
  
'''Authors:'''
+
Bernhard is a cyber security specialist with a talent in hacking all kinds of systems. During more than a decade in the industry, he has published many zero-day exploits for software such as MS SQL Server, Adobe Flash Player, IBM Director, Cisco VOIP and ModSecurity. If you can name it, he has probably broken it at least once. His pioneering work in mobile security was commended with a BlackHat "Best Research" Pwnie Award.
 +
 
 +
====  Sven Schleier ====
 +
 
 +
Sven is an experienced penetration tester and security architect who specialized in implementing secure SDLC for web application, iOS and Android apps. He is a project leader for the OWASP Mobile Security Testing Guide and the creator of OWASP Mobile Hacking Playground. Sven also supports the community with free hands-on workshops on web and mobile app security testing. He has published several security advisories and a white papers about a range of security topics.
 +
 
 +
=== Co-Authors ===
 +
 
 +
Co-authors have consistently contributed quality content, and have at least 2,000 additions logged in the GitHub repository.
 +
 
 +
==== Romuald Szkudlarek ====
 +
 
 +
Romuald is a passionate cyber security & privacy professional with over 15 years of experience in the Web, Mobile, IoT and Cloud domains. During his career, he has been dedicating spare time to a variery of projects with the goal of advancing the sectors of software and security. He is also teaching at various institutions. He holds CISSP, CSSLP and CEH credentials.
 +
 
 +
==== Jeroen Willemsen ====
 +
 
 +
Jeroen is a full-stack developer specialized in IT security at Xebia with a passion for mobile and risk management. He loves to explain things: starting as a teacher teaching PHP to bachelor students and then move along explaining security, risk management and programming issues to anyone willing to listen and learn.
  
* Bernhard Mueller
+
=== Top Contributors ===
* Sven Schleier
 
  
'''Co-Authors:'''
+
Top contributors have consistently contributed quality content with at least 500 additions logged in the GitHub repository.
* Romuald Szkudlarek
 
  
'''Top Contributors:'''
 
 
* Francesco Stillavato
 
* Francesco Stillavato
 
* Pawel Rzepa
 
* Pawel Rzepa
 +
* Andreas Happe
 
* Henry Hoggard
 
* Henry Hoggard
 +
* Wen Bin Kong
 
* Abdessamad Temmar
 
* Abdessamad Temmar
 +
* Alexander Anthuk
 
* Slawomir Kosowski
 
* Slawomir Kosowski
 +
* Bolot Kerimbaev
  
'''Contributors:'''
+
=== Contributors ===
* Andreas Happe
 
* Wen Bin Kong
 
* Jin Kung Ong
 
* Gerhard Wagner
 
* Michael Helwig
 
* Jeroen Willemsen
 
* Alexander Antukh
 
* Ryan Teoh
 
* Daniel Ramirez Martin
 
* Claudio André
 
* Prathan Phongthiproek
 
* Luander Ribeiro
 
* Dharshin De Silva
 
* Oguzhan Topgul
 
* Pishu Mahtani
 
* Anuruddha (L3Osi13nT)
 
  
'''Reviewers:''' Anant Shrivastava
+
Contributors have made a quality contribution with at least 50 additions logged in the GitHub repository.
  
This list includes everyone who committed 50+ lines of content. The full list of contributors is [https://github.com/OWASP/owasp-mstg/graphs/contributors available on GitHub].
+
Jin Kung Ong, Gerhard Wagner, Andreas Happe, Wen Bin Kong, Michael Helwig, Jeroen Willemsen, Denis Pilipchuk, Ryan Teoh, Dharshin De Silva, Anita Diamond, Daniel Ramirez Martin, Claudio André, Enrico Verzegnassi, Prathan Phongthiproek, Tom Welch, Luander Ribeiro, Oguzhan Topgul, Carlos Holguera, David Fern, Pishu Mahtani, Anuruddha
  
=== MSTG "Beta 2" on Google Drive ===
+
=== Reviewers ===
  
'''Authors:'''
+
Reviewers have consistently provided useful feedback through GitHub issues and pull request comments.
  
* Mirza Ali
 
* Stephen Corbiaux
 
* Ryan Dewhurst
 
* Mohammad Hamed Dadpour
 
* David Fern
 
* Ali Yazdani
 
* Bao Lee
 
* Anto Joseph
 
* Nutan Kumar Panda
 
* Rahil Parikh
 
* Julian Schütte
 
* Abhinav Sejpal
 
 
* Anant Shrivastava
 
* Anant Shrivastava
* Pragati Singh
+
* Sjoerd Langkemper
* Milan Singh Thakur
 
* Stephanie Vanroelen
 
* Gerhard Wagner
 
  
'''Reviewers:'''
+
=== Others ===
 +
 
 +
Many other contributors have committed small amounts of content, such as a single word or sentence (less than 50 additions). The full list of contributors is available on [https://github.com/OWASP/owasp-mstg/graphs/contributors GitHub].
  
* Andrew Muller
+
=== Old Version - MSTG "Beta" on Google Drive ===
* Jonathan Carter
 
* Stephanie Vanroelen
 
* Milan Singh Thakur
 
  
=== MSTG "Beta 1" on Google Drive ===
+
The Mobile Security Testing Guide was initiated by  [https://www.owasp.org/index.php/User:Milan_Singh_Thakur Milan Singh Thakur] in 2015. The original document was hosted on Google Drive.
  
'''Authors:'''  
+
'''Authors:'''
  
*Mirza Ali  
+
Mirza Ali, Stephen Corbiaux, Ryan Dewhurst, Mohammad Hamed DadpourDavid Fern, Ali Yazdani, Bao Lee, Anto Joseph, Nutan Kumar Panda, Rahil Parikh, Julian Schütte, Abhinav Sejpal, Anant Shrivastava, Pragati SinghMilan Singh Thakur, Stephanie Vanroelen, Gerhard Wagner
*Mohammad Hamed Dadpour
 
*David Fern
 
*Rahil Parikh
 
*Abhinav Sejpal
 
*Pragati Singh
 
*Milan Singh Thakur
 
  
 
'''Reviewers:'''
 
'''Reviewers:'''
  
*Andrew Muller
+
Andrew Muller, Jonathan Carter, Stephanie Vanroelen, Milan Singh Thakur
*Jonathan Carter
 
 
 
'''Top Contributors:'''
 
 
 
*Jim Manico
 
*Yair Amit
 
*Amin Lalji
 
*OWASP Mobile Team
 
 
 
 
 
  
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
 
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->

Revision as of 16:15, 16 June 2017

OWASP MSTG Header.jpg

Our Vision

"Define the industry standard for mobile application security."

We are writing a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.

Preview Release

Bites.jpg Mobile Security Testing Guide - OWASP Summit Preview

The Summit Preview contains sample chapters on Android security testing and reverse engineering. Feel free to download it for $0 or contribute any amount you like. All funds raised through sales of this book go directly into the project budget and will be used to fund production of the final release.

Main Deliverables

Mstg-mini-2.jpg Mobile Security Testing Guide

A comprehensive guide for iOS and Android mobile security testers with the following content:

  1. Mobile platform internals
  2. Security testing in the mobile app development lifecycle
  3. Basic static and dynamic security testing
  4. Mobile app reverse engineering and tampering
  5. Assessing software protections
  6. Detailed test cases that map to the requirements in the MASVS.

The MSTG is a work-in-progress. Currently, we hope to be "feature-complete" in Q3 2017. You can contribute and comment in the GitHub Repo. A book version of the current master branch is available on Gitbook.

Masvs-sample-mini.jpg Mobile App Security Requirements and Verification

The OWASP Mobile Application Security Verification Standard (MASVS) is a standard for mobile app security. It can be used by mobile software architects and developers seeking to develop secure mobile applications, as well as security testers to ensure completeness and consistency of test results. The latest release is version 0.9.3.

Checklist.jpg Mobile App Security Checklist

A checklist for use in security assessments. Also contains links to the MSTG test case for each requirement. The current release is version 0.9.3.


Classifications

Owasp-breakers-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg

Project Leaders

Bernhard Mueller

Sven Schleier

Road Map

  • Q3 2017: Beta release
  • Q4 2017: Version 1.0
  • Q1 2018: Produce A Printable Book

Parent Project

OWASP_Mobile_Security_Project

Licensing

The guide is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.