DEV Community

Discussion on: Offensive security on an Android app

Collapse
 
exadra37 profile image
Paulo Renato

I really loved this article... Cannot wait to read the others ;)

Did you already tried to use truffleHog to search for secrets in a code base?

Did you ever tried the Mobile Security Framework to decompile and analyze an APK for security and potential secrets?

PS: the mitmproxy link needs the markdown fixed

Collapse
 
shostarsson profile image
Rémi Lavedrine

Thanks for pointing out the badly linked "mitmproxy".
Solved by now. :-)

Collapse
 
shostarsson profile image
Rémi Lavedrine

Yes, I used TruffleHog (among others) to search for secrets in a codebase.
I am a heavy user of MobSF, that I modified slightly to automate the process to a bunch of apps at once.
It is working pretty well. One of my colleague is a MobSF contributor by the way. We are working on this in my department.

Collapse
 
exadra37 profile image
Paulo Renato

Oh very nice to know... now I know to who I can complain to ;)