This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Mobile Security Testing Guide"
From OWASP
Cpholguera (talk | contribs) (moved Carlos Holguera) |
m (→Main Deliverables) |
||
(13 intermediate revisions by 3 users not shown) | |||
Line 8: | Line 8: | ||
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | ||
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;" | | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;" | | ||
+ | |||
+ | == Maintenance notice == | ||
+ | |||
+ | This site is no longer maintained: please go to https://www2.owasp.org/www-project-mobile-security-testing-guide/ for our new website! | ||
+ | |||
==Our Vision == | ==Our Vision == | ||
Line 39: | Line 44: | ||
| [[File:checklist.jpg|link=https://github.com/OWASP/owasp-mstg/tree/master/Checklists]] | | [[File:checklist.jpg|link=https://github.com/OWASP/owasp-mstg/tree/master/Checklists]] | ||
| '''Mobile App Security Checklist''' | | '''Mobile App Security Checklist''' | ||
− | A checklist for use in security assessments. Also contains links to the MSTG test case for each requirement. The current release is [https://github.com/OWASP/owasp-mstg/tree/master/Checklists can be found at Github in English, French, Spanish and | + | A checklist for use in security assessments. Also contains links to the MSTG test case for each requirement. The current release is [https://github.com/OWASP/owasp-mstg/tree/master/Checklists can be found at Github in English, French, Spanish, Japanese and Korean]. |
|} | |} | ||
Line 169: | Line 174: | ||
=News= | =News= | ||
+ | |||
+ | ==October 2nd, 2019: MSTG Playground release! == | ||
+ | Want more training apps? We hear you! We just released the MSTG-Android-Java & MSTG-Android-Kotlin for Android and the MSTG-JWT app for iOS. Come and check it out at [https://github.com/OWASP/MSTG-Hacking-Playground/releases the release page] ! With special thanks to Sven Schleier(@sushi2k), Wen Bin Kong (@kongwenbin), Nikhil Soni (@nikhil), and Ryan Teoh (@ryantzj)! | ||
+ | |||
+ | ==October 2nd, 2019: MSTG Project joins Hacktoberfest! == | ||
+ | We are joining the #hacktoberfest October 2-31. Check out our issues [https://github.com/OWASP/owasp-mstg/labels/Hacktoberfest at Github]. Register at https://hacktoberfest.digitalocean.com. | ||
+ | |||
+ | ==September 17th, 2019: Xamarin experiment! == | ||
+ | We have launched a react-native experiment based on our compliancy checklist. Want to teach others how to validate React NAtive apps against the MASVS? Check [https://drive.google.com/open?id=1UL1yLRREJwXfe0HlrcX-IuvPYQM7lTtG this Google sheet]!. | ||
+ | |||
+ | == September 6th, 2019: Flutter experiment! == | ||
+ | We have launched a react-native experiment based on our compliancy checklist. Want to teach others how to validate React NAtive apps against the MASVS? Check [https://drive.google.com/open?id=1wHK3VI1cU1xmYrCu9yb5OHKUEeLIPSkC this Google sheet]!. | ||
+ | |||
+ | == September 6th, 2019: React native experiment! == | ||
+ | We have launched a react-native experiment based on our compliancy checklist. Want to teach others how to validate React NAtive apps against the MASVS? Check [https://drive.google.com/open?id=1P5FZ_Bup5eSPOmkePZA8cIpKGOKvngkN this Google sheet]!. | ||
+ | |||
+ | == August 29th, 2019: Carlos Holguera joins the leaderteam == | ||
+ | We are happy to announce that Carlos Holguera joins us as an official MSTG Author and co-leader! With a team of 3 we hope to march further as that would make our lives easier given that all of this hard work is done by volunteers! | ||
== August 4th, 2019: OSS Release! == | == August 4th, 2019: OSS Release! == | ||
Line 380: | Line 403: | ||
Drop a us line on the [https://owasp.slack.com/messages/project-mobile_omtg/details/) Slack channel] before you start working on a topic. This helps us to keep track of what everyone is doing and prevent conflicts. You can create a Slack account here: | Drop a us line on the [https://owasp.slack.com/messages/project-mobile_omtg/details/) Slack channel] before you start working on a topic. This helps us to keep track of what everyone is doing and prevent conflicts. You can create a Slack account here: | ||
− | [https:// | + | [https://join.slack.com/t/owasp/shared_invite/enQtNjExMTc3MTg0MzU4LWQ2Nzg3NGJiZGQ2MjRmNzkzN2Q4YzU1MWYyZTdjYjA2ZTA5M2RkNzE2ZjdkNzI5ZThhOWY5MjljYWZmYmY4ZjM owasp slack invite] |
Before you start contributing, please read our brief [https://github.com/OWASP/owasp-mstg/blob/master/style_guide.md style guide] which contains a few basic writing rules. | Before you start contributing, please read our brief [https://github.com/OWASP/owasp-mstg/blob/master/style_guide.md style guide] which contains a few basic writing rules. | ||
Line 396: | Line 419: | ||
* Developing tools. For example, we still don't have an automated way of generating checklists out of the GitHub repo. | * Developing tools. For example, we still don't have an automated way of generating checklists out of the GitHub repo. | ||
− | * Contributing to auxiliary projects: | + | * Contributing to auxiliary projects: There are various projects that we support at this moment, consider: [https://github.com/OWASP/Mobile-Threatmodel the mobile threatmodel project] and our own [https://github.com/OWASP/MSTG-Hacking-Playground Hacking playground]. In the past, there was the [https://github.com/b-mueller/obfuscation-metrics obfuscation metrics project] is an auxiliary project that deals with specific forms of control flow and data obfuscation. This project needs experts in advanced obfuscation / de-obfuscation. Please contact us if you have experience in this area. |
==If I am not a programmer can I participate in your project?== | ==If I am not a programmer can I participate in your project?== | ||
Line 444: | Line 467: | ||
* Kyle Benac | * Kyle Benac | ||
* Alexander Anthuk | * Alexander Anthuk | ||
− | |||
* Wen Bin Kong | * Wen Bin Kong | ||
* Abdessamad Temmar | * Abdessamad Temmar |