CODE Security offers security tests and reviews of iOS and Android applications, including classical mobile apps, MDM solutions, low-level operating system specifics and kernels. The OWASP Mobile Top 10 security risks provide the backbone of the mobile applications security assessment services we provide for our clients. This includes, but is not limited to, covering the following areas:
- Improper platform use
- Insecure data storage on the mobile device
- Inadequate protection of the transport layer
- Insecure / weak authentication methods
- Sources of error in cryptography
- Insecure / weak authorization methods
- Identification of vulnerabilities in the source code of the mobile application
- Manipulation of code or application data
- Reverse engineering
- Identification of potentially security-endangering, hidden functions (e.g., hidden backdoor)
Similar to web application penetration tests, to further increase the effectiveness, CODE Security encourages combining dynamic testing with a static source code review in order to achieve the most comprehensive coverage.