Posts on mobile-security
9 posts on mobile-security. Notes from public sources and my own test lab.
Trusting Automated Scanners? Welcome to the Illusionary World of Mobile Security
Relying solely on automated security tools is like sailing a paper boat in a storm. Let's talk about why manual testing and defensive depth matter more than flashy PDF reports.
The False Peace of the Sandbox: Why Automation Won't Save You in Mobile Security
Automated scans like MobSF aren't a silver bullet. True mobile security requires looking beyond the sandbox and understanding how real attackers bypass 'secure' local storage and SSL pinning.
Spy in Your Pocket: Did You Hand Over the Keys to Your Mobile App's Backdoor?
Think your compiled mobile app is a secure black box? Think again. We're diving into binary security illusions and the pitfalls of local data storage from a Red Team perspective.
Cebimizdeki Casuslar: Mobil Güvenliğin Görünmeyen Yüzü ve Tersine Mühendislik Maceraları
Mobil uygulamalarda 'güvenli' sandığımız o alanların aslında ne kadar kırılgan olduğunu, kendi yaptığım hatalardan yola çıkarak anlatıyorum. Tersine mühendislikten SSL pinning'e kadar sahada karşılaştığımız gerçekleri konuşalım.
The Trojan in Our Pockets: The Illusion of 'Security' in Mobile Apps
Mobile security is a different beast altogether. Your code isn't behind a firewall; it's sitting in the attacker's living room. Let's talk about why 'hardcoded' is a dirty word and how SSL Pinning isn't the silver bullet you think it is.
The Trojan in Our Pocket: Getting Blindsided in Mobile App Security
It's past midnight, your Frida scripts are failing, and the app keeps crashing. Think SSL Pinning is an impenetrable wall? Think again. Let's dive into the 'wild' world of mobile security through the lens of a Red Teamer.
Trojan Horses in Our Pockets: Mobile App Security Blunders We Swear We'd Never Make
From mistaking public API keys for crown jewels to the 'allowBackup' trap, let's dive into some common mobile security pitfalls I've seen in the field—and how to avoid them.
The Trojan in Our Pockets: The Unseen Side of Mobile Security and the 'Safe' Pitfalls
Mobile security is more than just FaceID. From hardcoded secrets in APKs to sensitive data leaking in SharedPreferences, let's dive into the defensive side of mobile app development through the eyes of a Red Teamer.
Walking the Minefield: From Reverse Engineering to Runtime Manipulation
Mobile security is more than just decompiling APKs. Here is my journey from being a rookie to mastering the art of runtime manipulation with Frida.