Robuta

https://mas.owasp.org/MASTG/best-practices/MASTG-BEST-0040/ MASTG-BEST-0040: Preventing Overlay Attacks - OWASP Mobile Application Security mobile applicationbestpreventingoverlayattacks https://mas.owasp.org/MASTG/tests/ios/MASVS-STORAGE/MASTG-TEST-0313/ MASTG-TEST-0313: References to APIs for Preventing Keyboard Caching of Text Fields - OWASP Mobile... https://mas.owasp.org/MASTG/demos/ios/MASVS-CODE/MASTG-DEMO-0052/MASTG-DEMO-0052/ MASTG-DEMO-0052: Scanning Package Manager Artifacts for Insecure iOS Dependencies - OWASP Mobile... https://mas.owasp.org/MASTG/demos/android/MASVS-PLATFORM/MASTG-DEMO-0061/MASTG-DEMO-0061/ MASTG-DEMO-0061: Uses of FLAG_SECURE with semgrep - OWASP Mobile Application Security https://mas.owasp.org/MASTG/tools/generic/MASTG-TOOL-0132/ MASTG-TOOL-0132: dependency-track - OWASP Mobile Application Security mobile applicationtooldependencytrackowasp https://mas.owasp.org/MASTG/tests/ios/MASVS-PRIVACY/MASTG-TEST-0281/ MASTG-TEST-0281: Undeclared Known Tracking Domains - OWASP Mobile Application Security mobile applicationtestundeclaredknown https://mas.owasp.org/MASTG/tests/android/MASVS-AUTH/MASTG-TEST-0326/ MASTG-TEST-0326: References to APIs Allowing Fallback to Non-Biometric Authentication - OWASP... https://mas.owasp.org/MASTG/demos/ios/MASVS-PLATFORM/MASTG-DEMO-0098/MASTG-DEMO-0098/ MASTG-DEMO-0098: References to File Access in WebViews with radare2 - OWASP Mobile Application... https://mas.owasp.org/MASTG/techniques/android/MASTG-TECH-0148/ MASTG-TECH-0148: Interacting with Android ContentProviders - OWASP Mobile Application Security mobile applicationtechinteracting https://mas.owasp.org/MASTG/tests/android/MASVS-CODE/MASTG-TEST-0338/ MASTG-TEST-0338: Integrity and Authenticity Validation of Local Storage Data - OWASP Mobile... https://mas.owasp.org/MASTG/techniques/android/MASTG-TECH-0032/ MASTG-TECH-0032: Execution Tracing - OWASP Mobile Application Security mobile applicationtechexecutiontracingowasp https://mas.owasp.org/MASTG/tests/android/MASVS-CRYPTO/MASTG-TEST-0205/ MASTG-TEST-0205: Non-random Sources Usage - OWASP Mobile Application Security mobile applicationtestnonrandom https://mas.owasp.org/MASTG/tests/android/MASVS-RESILIENCE/MASTG-TEST-0225/ MASTG-TEST-0225: Usage of Insecure APK Signature Key Size - OWASP Mobile Application Security https://mas.owasp.org/MASTG/demos/android/MASVS-STORAGE/MASTG-DEMO-0070/MASTG-DEMO-0070/ MASTG-DEMO-0070: Sensitive Data Stored Unencrypted via Room Database - OWASP Mobile Application... https://mas.owasp.org/MASTG/demos/android/MASVS-CODE/MASTG-DEMO-0101/MASTG-DEMO-0101/ MASTG-DEMO-0101: Local Storage for Input Validation with semgrep - OWASP Mobile Application Security https://mas.owasp.org/MASTG/demos/android/MASVS-PLATFORM/MASTG-DEMO-0105/MASTG-DEMO-0105/ MASTG-DEMO-0105: Activity-Level Overlay Protection Using setHideOverlayWindows - OWASP Mobile... activity leveldemo https://mas.owasp.org/MASTG/knowledge/android/MASVS-STORAGE/MASTG-KNOW-0039/ MASTG-KNOW-0039: Firebase Real-time Databases - OWASP Mobile Application Security real timemobile applicationknowfirebase https://mas.owasp.org/MASTG/demos/ios/MASVS-AUTH/MASTG-DEMO-0044/MASTG-DEMO-0044/ MASTG-DEMO-0044: Runtime Use of kSecAccessControlUserPresence with Frida - OWASP Mobile Application... https://mas.owasp.org/MASTG/tests/ios/MASVS-STORAGE/MASTG-TEST-0296/ MASTG-TEST-0296: Sensitive Data Exposure Through Insecure Logging - OWASP Mobile Application... sensitive data exposure https://mas.owasp.org/MASTG/demos/ios/MASVS-CRYPTO/MASTG-DEMO-0074/MASTG-DEMO-0074/ MASTG-DEMO-0074: Uses of Insecure Random Number Generation with frida-trace - OWASP Mobile... https://mas.owasp.org/MASTG/tests/android/MASVS-RESILIENCE/MASTG-TEST-0325/ MASTG-TEST-0325: Runtime Use of Root Detection Techniques - OWASP Mobile Application Security https://mas.owasp.org/MASTG/demos/ios/MASVS-PLATFORM/MASTG-DEMO-0099/MASTG-DEMO-0099/ MASTG-DEMO-0099: Runtime Monitoring of WebView File Access with Frida - OWASP Mobile Application... https://mas.owasp.org/MASTG/apps/android/MASTG-APP-0002/ MASTG-APP-0002: Android License Validator - OWASP Mobile Application Security mobile applicationandroidlicensevalidatorowasp https://mas.owasp.org/MASTG/demos/android/MASVS-CODE/MASTG-DEMO-0102/MASTG-DEMO-0102/ MASTG-DEMO-0102: SQL Injection via URI Path and Selection in Android Content Providers - OWASP... https://mas.owasp.org/MASTG/demos/ios/MASVS-NETWORK/MASTG-DEMO-0085/MASTG-DEMO-0085/ MASTG-DEMO-0085: Uses of Network Framework Bypassing ATS - OWASP Mobile Application Security https://mas.owasp.org/MASTG/demos/ios/MASVS-CRYPTO/MASTG-DEMO-0073/MASTG-DEMO-0073/ MASTG-DEMO-0073: Uses of Insecure Random Number Generation with r2 - OWASP Mobile Application... https://mas.owasp.org/MASTG/tools/network/MASTG-TOOL-0143/ MASTG-TOOL-0143: badssl - OWASP Mobile Application Security mobile applicationtoolowaspsecurity https://mas.owasp.org/MASTG/tools/ios/MASTG-TOOL-0137/ MASTG-TOOL-0137: GlobalWebInspect - OWASP Mobile Application Security mobile applicationtoolowaspsecurity https://mas.owasp.org/MASTG/tests/android/MASVS-CODE/MASTG-TEST-0339/ MASTG-TEST-0339: SQL Injection in Content Providers - OWASP Mobile Application Security sql injection https://mas.owasp.org/MASTG/demos/android/MASVS-CODE/MASTG-DEMO-0100/MASTG-DEMO-0100/ MASTG-DEMO-0100: Object Deserialization Using Serializable with semgrep - OWASP Mobile Application... https://mas.owasp.org/MASTG/tests/ios/MASVS-STORAGE/MASTG-TEST-0302/ MASTG-TEST-0302: Sensitive Data Unencrypted in Private Storage Files - OWASP Mobile Application... https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0336/ MASTG-TEST-0336: Runtime Setting of Relaxed WebView File Origin Policies - OWASP Mobile Application... https://mas.owasp.org/MASTG/tests/android/MASVS-NETWORK/MASTG-TEST-0217/ MASTG-TEST-0217: Insecure TLS Protocols Explicitly Allowed in Code - OWASP Mobile Application... https://mas.owasp.org/MASTG/demos/ios/MASVS-CODE/MASTG-DEMO-0053/MASTG-DEMO-0053/ MASTG-DEMO-0053: Identifying Insecure Dependencies in SwiftPM through SBOM creation - OWASP Mobile... https://mas.owasp.org/MASTG/demos/ios/MASVS-PLATFORM/MASTG-DEMO-0095/MASTG-DEMO-0095/ MASTG-DEMO-0095: Attacker-Controlled Input in a WebView Leading to Unintended Navigation - OWASP... https://mas.owasp.org/MASTG/tests/android/MASVS-PRIVACY/MASTG-TEST-0318/ MASTG-TEST-0318: References to SDK APIs Known to Handle Sensitive User Data - OWASP Mobile... https://mas.owasp.org/MASTG/tests/android/MASVS-PLATFORM/MASTG-TEST-0316/ MASTG-TEST-0316: App Exposing User Authentication Data in Text Input Fields - OWASP Mobile... https://mas.owasp.org/MASTG/demos/ios/MASVS-STORAGE/MASTG-DEMO-0077/MASTG-DEMO-0077/ MASTG-DEMO-0077: Runtime Monitoring of Text Fields Eligible for Keyboard Caching with Frida - OWASP... https://mas.owasp.org/MASTG/knowledge/android/MASVS-STORAGE/MASTG-KNOW-0051/ MASTG-KNOW-0051: Process Memory - OWASP Mobile Application Security mobile applicationknowprocessmemoryowasp https://mas.owasp.org/MASTG/knowledge/ios/MASVS-STORAGE/MASTG-KNOW-0096/ MASTG-KNOW-0096: Realm Databases - OWASP Mobile Application Security mobile applicationknowrealmdatabasesowasp