MobSF for penetration testers
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Show slide in full page or toggle automatic source change | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
MobSF is a free and OpenSource security scanner for mobile application. First, this talk will introduce MobSF and its different features. Then, the talk will present how MobSF can be used during a penetration test or a red team. After presenting how to setup the tool for penetration testing, different use cases will be presented, regarding two different points of view: - a security review of a mobile application (or an SDK), in this case, the mobile application or the specific SDK is the target. - an assessment where the mobile application is not directly the target, in this case, the mobile application is used for recon (and more). - a quick use case of usage for every penetration tester who don't want to dig into complex android methods These use cases will also point MobSF limits and how to handle them by using the API and homemade scripts. For some cases, a comparison with other tools (such as apkleaks) will be done. At last, a quick review of how bug report and feature requests are handled by the MobSF team.
Antoine is a penetration tester at Synacktiv. He enjoys computer science, electronics and D.I.Y., beers (drinking and making) by night… and he’s fond of cigars!
Pentester at Synacktiv
Other media in the channel "2022"
- 21 views, 2 this year, 1 this monthClosingJuly 6th, 2022
- 56 views, 10 this yearkdigger: A Context Discovery Tool for Kubernetes Penetration TestingJuly 6th, 2022
- 45 views, 6 this yearDissecting NTLM EPA & building a MitM proxyJuly 6th, 2022
- 82 views, 23 this year, 1 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
- 81 views, 8 this year, 1 this monthImprove your Malware Recipes with CyberchefJuly 6th, 2022
- 417 views, 128 this year, 16 this monthTAPIR : Trustable Artifact Parser for Incident ResponseJuly 6th, 2022