EPISODE · Nov 13, 2018 · 28 MIN
Swaroop Yermalkar -- iGoat and iOS Mobile Pen Testing
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Mobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes. OWASP iGoat project leader Swaroop Yermalkar joins Chris to explain how he approaches testing iOS and Swift applications, starting with understanding the business and following the data. They discuss hardcoded cloud keys, inspecting application classes, proxying traffic, and weaknesses in mobile service endpoints. Swaroop then introduces iGoat as a practical learning environment where people can exploit a flaw, understand the remediation, and rebuild the application with a fix. A cloud-storage exercise illustrates how client-side clues lead to a wider exposure. The episode closes with iGoat’s relationship to OWASP’s mobile guidance and why these skills matter across Apple’s expanding device ecosystem.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Swaroop Yermalkar:→ Swaroop Yermalkar on LinkedIn→ OWASP iGoatMentioned in this episode:→ iGoat Swift→ OWASP Mobile Application Security Testing Guide→ Burp Suite→ OWASP WebGoatFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 iOS security and iGoat with Swaroop Yermalkar01:11 From Wi-Fi curiosity to application security02:42 Mobile applications in bug bounty programs03:44 Testing Swift applications05:01 Hardcoded keys and excessive permissions07:45 Understanding the business before testing10:51 Inspecting and decrypting an iOS application12:24 Static analysis and proxying mobile traffic13:58 Why mobile backends deserve attention15:53 What the iGoat learning environment contains17:57 Fixing the vulnerability after exploiting it19:13 A cloud-storage misconfiguration exercise23:18 Future directions and new challenges24:49 Connecting iGoat with OWASP mobile standards26:24 Applying the skills across devices
Embed this episode
What this episode covers
Mobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes. OWASP iGoat project leader Swaroop Yermalkar joins Chris to explain how he approaches testing iOS and Swift applications, starting with understanding the business and following the data. They discuss hardcoded cloud keys, inspecting application classes, proxying traffic, and weaknesses in mobile service endpoints. Swaroop then introduces iGoat as a practical learning environment where ...
Ready to play
Swaroop Yermalkar -- iGoat and iOS Mobile Pen Testing
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.