Android Application Penetration Testing  - Android Penetration Testing - Android Application Penetration Testing- Pentesting Series

In Last Part Android Application Penetration Testing Part 6 We have seen about the has been categorized as TOP 10.

INSECURE LOGGING- ADB Logcat:

Logcat is a command-line tool that dumps a log of system messages, including stack traces when the device throws an error and messages that you have written from your app with the Log class.

Logcat allows you to:

  • View, filter and collect all application logs
  • View, filter and collect all system logs such as the garbage collector events
  • Retrieve all unexpected errors that have occurred

Sometimes when you are logging into the application. Those credentials can be found in logs.

Mitigation: adb logcat -c” (This clears the logs.) But make sure while coding an application credentials should not be displayed in logs.

Insecure external and internal storage

As we already know all data of the application in the device can be found in /data/data directory and all applications (apk files) in device can be found in /data/app directory.

When you have rooted device you can go in depth to see which kind of files stored in this directories.

Internal Storage

Internal storage is another way of storing data in Android . Developers can store data in Android applications locally in various ways

Examples

Shared preferences, files, Cache, SQLite databases, lib, log files, Binary data stores, cookie stores etc.

Shared Preferences

“Shared Preferences” allows a developer to save and retrieve persistent key-value pairs of primitive data types such as Booleans, floats, ints, longs, and strings.Shared preferences are created in Android applications using the Shared Preferences class.

Sq-lite Databases

Sq-lite databases are lightweight file-based databases. They usually have the extension “.db” or “.sq-lite”. Android provides full support for Sq-lite databases. Databases we create in the application will be accessible to any class in the application. Other apps cannot access them.

- 14 10 2017 21 55 41 - Android Application Penetration Testing- Pentesting Series

- 14 10 2017 22 12 00 - Android Application Penetration Testing- Pentesting Series

External Storage

SDCARD is another important location in Android where we can store data associated with our applications. Files created on external storage are globally readable and writable. Because external storage can be removed by the user and also modified by any application, you should not store sensitive information using external storage.

- 14 10 2017 22 44 43 - Android Application Penetration Testing- Pentesting Series

Mitigation:

  • For local storage the enterprise android device administration API can be used to force encryption to local files stores “set storage encryption”
  • Ensure any shared preferences properties are NOT_MODE_WORLD_READABLE unless explicitly required for information sharing between apps
  • For SD CARD storage some can be achieved via the ‘javax.crypto’ library.

Insecure Communication

Lack of Certificate Inspection: Android Application fails to verify the identity of the certificate presented to it. Most of the application ignore the warnings and accept any self-signed certificate presented. Some Application instead pass the traffic through an HTTP connection.

Weak Handshake Negotiation: Application and server perform an SSL/TLS handshake but use an insecure cipher suite which is to MITM attacks. So any attacker can easily decrypt that connection.

Privacy Information Leakage: Most of the times it happens that Applications do authentication through a secure channel but rest all connection through non-secure channel. That doesn’t add to security of application because rest sensitive data like session cookie or user data can be intercepted by a malicious user.

- Screenshot from 2017 10 14 193559 - Android Application Penetration Testing- Pentesting Series

Mitigation:

  • Use certificates signed by a trusted CA provider and consider certificate pinning for security conscious applications.
  • Apply SSL/TLS to transport channels that the mobile app will use to transmit sensitive information, session tokens, or other sensitive data to a backend API or web service.
  • Only establish a secure connection after verifying the identity of end point server using trusted certificates in the key chain.

Other Parts :



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here