Bishop Fox
Mobile Application Assessment Methodology
Pages
5
Time to read
6 mins
Publication
Language
English
Pages
5
Time to read
6 mins
Publication
Language
English
This document is a technical report detailing Bishop Fox's mobile application assessment methodology, which aims to identify security weaknesses in mobile applications and their infrastructure. The assessment process includes zero-, partial-, or full-knowledge evaluations that start with the enumeration and analysis of applications within an organization. The assessment team employs both industry-standard and proprietary tools, alongside expert-guided testing techniques, to discover vulnerabilities. Following the identification of weaknesses, manual exploitation is conducted to compromise sensitive data and systems. The methodology outlines several phases, including discovery and testing, manual testing, information gathering, mobile penetration testing, and analysis and reporting. The report emphasizes the importance of pre-assessment requirements, such as client architecture documentation and application details, to ensure a thorough evaluation. The final report includes a summary of findings, remediation recommendations, and an analysis of the impact of identified vulnerabilities on the organization.