Skip to content

TODO List #1

@wargio

Description

@wargio

Android

  • Check APK Signature
    • rizin can open META-INF/CERT.RSA and print the pkcs7 data from pFp
  • Check Certificates and validity, bad hashes, etc..
  • Detect trackers
  • App is debuggable example
  • Exported example issue - Partial
  • Test all android security best practies link

iOS

  • Weak rand function
  • Sandbox Behavior (like successfully use fork() because calls to fork() are disallowed on a stock iOS device).
  • TrustKit pinning.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions