Bug’s Life — Field Guide to Vulnerabilities
← Field Guide Index
SPC-03MOBILE

Mobile App Pentesting

Classification
MOBILE
Method
By hand
Standards
OWASP · PTES
Duration
1–4 weeks
01 · Field Notes
Overview

What this engagement covers

Mobile apps expose data and logic on devices you do not control. We test your iOS and Android applications the way an attacker would — inspecting the client, its storage, and how it talks to your backend — to find issues before your users or their attackers do.

02 · Test Coverage
What we test
Data storage & privacy
  • Insecure local storage — Keychain/Keystore, databases, files, caches
  • Sensitive data in logs, backups, screenshots and the clipboard
  • Hardcoded secrets, API keys and credentials in the binary
Cryptography & authentication
  • Weak or misused cryptography and poor key management
  • Authentication and biometric / local-auth bypass
  • Session and token handling flaws
Network communication
  • TLS validation and certificate pinning (MITM resistance)
  • Insecure API traffic and data exposure in transit
Platform & code
  • Insecure IPC, deep links and exported components
  • WebView and JavaScript-bridge issues
  • Reverse-engineering, tampering, root/jailbreak and anti-debugging resistance
  • The backend APIs the app relies on (authorization, data exposure)
Platforms
  • iOS and Android, aligned to the OWASP MASVS
  • Black-box (compiled build) or grey/white-box (source & creds)
03 · Specimen Range
Scope of work
  • a.Static and dynamic analysis of iOS and Android builds
  • b.Insecure data storage, logging and secrets review
  • c.API and backend communication testing
  • d.Authentication, session and authorization checks
  • e.Aligned to the OWASP Mobile Application Security standard (MASVS)
04 · Field Method
How we work
01

Scope & rules of engagement

We agree targets, timing, depth and constraints in writing before anything starts — so testing is safe, authorized and focused on what matters to you.

02

Manual testing

Certified testers work by hand — following recognised methodologies like OWASP and PTES, not just automated scanners — chaining findings the way a real attacker would to prove genuine impact.

03

Reporting

You get a prioritized report with clear proof-of-concept, business impact and step-by-step remediation your engineers can act on immediately.

04

Retest

After you fix, we re-test the findings to confirm they are resolved and issue an updated report you can share with customers or auditors.

05 · What you keep
Deliverables
  • Findings across the app, its storage and its APIs
  • Proof-of-concept for exploitable issues
  • Platform-specific remediation for iOS and Android
  • A customer-shareable report for due diligence and app reviews
  • Free retest after you ship the fixes
06 · Field Q&A
Common questions
Do you need our source code?

Not necessarily. We can test a compiled build (black-box) or work with source and credentials (grey/white-box) for deeper coverage — we will recommend the right depth for your goals.

Do you test the backend too?

Yes — the app’s APIs and backend are part of a mobile assessment, since that is where most of the sensitive logic and data actually lives.

Specimen request

Ready to get started with Mobile App Pentesting?