This is a summary of the tools that are described in OWASP Mobile Security M Tools page.
-
What is it?
-
iOS secure application framework research to reduce iOS application vulnerabilities and information loss
-
-
Source code
-
Modules
-
-
Cipherlib, crypto manager, keychain crypto
-
-
-
Custom iOS user authentication mechanism (password with security questions for self reset)
-
-
-
Allows an application to verify if an iOS passcode has been set and what complexity. Based on this, an application can programtically decide to execute fully or in a degraded state given this system evidence
-
-
-
Provides a Core Data encrypted SQLite store using SQLCipher.
-
-
-
Application level, attached debug detect and jailbreak checking
-
-
-
Library for securely clearing and validating iOS application memory
-
Elliminate clear-text sensitive data from memory after app use
-
-
-
What is it?
-
A fully functional and self-contained training environment for educating developers and testers on Android security
-
-
Source Code
-
What is it?
-
A safe environment where iOS developers can learn about the major security pitfalls they face as well as how to avoid them.
-
-
Source Code
-
What is it?
-
The MobiSec Live Environment Mobile Testing Framework project is a live environment for testing mobile environments, including devices, applications, and supporting infrastructure.
-
-
What is it?
-
Androick is a tool that allows any user to analyze an Android application
-
-
Soure Code
-
What is it?
-
It is the freely downloadable version of the powerful App Testing suite. Users are offered a number of features such as network capture, automation, import / export, and reporting to test and secure mobile apps
-
-
Tools
-
-
Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform
-
-
-
An app to scan vulnerabilities on Android
-
-
-
Inject JavaScript to explore native apps on Windows, macOS, Linux, iOS, Android, and QNX.
-
-
-
Portable reversing framework
-
-
The tools are very useful. We should try them.
The NowSecure website also provides some resources/handbooks that could be very helpful. E.g.
-
Mobile Banking Applications: Security Challenges for Banks
-
Mobile App Security Program Management Handbook