Movatterモバイル変換


[0]ホーム

URL:


MASTG Tests

About the MASTG Tests

The MASTG "Atomic Tests" are a new addition to the MAS project. They are a collection of small, individual tests that can be used to assess the security and privacy of a mobile application. Each test is designed to be simple and focused on a single issue. The goal is to make it easier for developers and security professionals to identify and fix issues in their mobile applications.

Tests are organized into categories based on theOWASP MASVS and have a weakness assigned from theOWASP MASWE.

Each test includes:

  • Overview: A brief description of the test.
  • Steps: A set of steps to follow to identify the weakness in a mobile application.
  • Observation: A description of the results of running the test against an application.
  • Evaluation: Specific instructions for evaluating the results of the test.

Each test comes with a collection of demos that demonstrate the weakness in a sample application. These demos are written in markdown and are located in theDemos section of the MASTG.

IDTitlePlatformL1L2RPStatus
MASTG-TEST-0231 References to Logging APIsplatform:androidprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0207 Runtime Storage of Unencrypted Data in the App Sandboxplatform:androidprofile:L2newstatus:new
MASTG-TEST-0012 Testing the Device-Access-Security Policyplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0304 Sensitive Data Stored Unencrypted via SQLiteplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0200 Files Written to External Storageplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0287 Sensitive Data Stored Unencrypted via the SharedPreferences API to the App Sandboxplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0006 Determining Whether the Keyboard Cache Is Disabled for Text Input Fieldsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0004 Determining Whether Sensitive Data Is Shared with Third Parties via Embedded Servicesplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0306 Sensitive Data Stored Unencrypted via Android Room DBplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0003 Testing Logs for Sensitive Dataplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0262 References to Backup Configurations Not Excluding Sensitive Dataplatform:androidprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0201 Runtime Use of APIs to Access External Storageplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0009 Testing Backups for Sensitive Dataplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0005 Determining Whether Sensitive Data Is Shared with Third Parties via Notificationsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0203 Runtime Use of Logging APIsplatform:androidprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0305 Sensitive Data Stored Unencrypted via DataStoreplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0216 Sensitive Data Not Excluded From Backupplatform:androidprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0011 Testing Memory for Sensitive Dataplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0001 Testing Local Storage for Sensitive Dataplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0202 References to APIs and Permissions for Accessing External Storageplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0206 Undeclared PII in Network Traffic Captureplatform:androidprofile:Pnewstatus:new
MASTG-TEST-0256 Missing Permission Rationaleplatform:androidprofile:Pplaceholderstatus:placeholder
MASTG-TEST-0255 Permission Requests Not Minimizedplatform:androidprofile:Pplaceholderstatus:placeholder
MASTG-TEST-0254 Dangerous App Permissionsplatform:androidprofile:Pnewstatus:new
MASTG-TEST-0257 Not Resetting Unused Permissionsplatform:androidprofile:Pplaceholderstatus:placeholder
MASTG-TEST-0033 Testing for Java Objects Exposed Through WebViewsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0008 Checking for Sensitive Data Disclosure Through the User Interfaceplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0037 Testing WebViews Cleanupplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0289 Runtime Verification of Sensitive Content Exposure in Screenshots During App Backgroundingplatform:androidprofile:L2newstatus:new
MASTG-TEST-0291 References to Screen Capturing Prevention APIsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0315 Sensitive Data Exposed via Notificationsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0293setSecure Not Used to Prevent Screenshots in SurfaceViewsplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0028 Testing Deep Linksplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0007 Determining Whether Sensitive Stored Data Has Been Exposed via IPC Mechanismsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0294SecureOn Not Used to Prevent Screenshots in Compose Dialogsplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0250 References to Content Provider Access in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0251 Runtime Use of Content Provider Access APIs in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0252 References to Local File Access in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0010 Finding Sensitive Information in Auto-Generated Screenshotsplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0253 Runtime Use of Local File Access APIs in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0029 Testing for Sensitive Functionality Exposure Through IPCplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0024 Testing for App Permissionsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0030 Testing for Vulnerable Implementation of PendingIntentplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0031 Testing JavaScript Execution in WebViewsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0316 App Exposing User Authentication Data in Text Input Fieldsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0032 Testing WebView Protocol Handlersplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0035 Testing for Overlay Attacksplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0258 References to Keyboard Caching Attributes in UI Elementsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0292setRecentsScreenshotEnabled Not Used to Prevent Screenshots When Backgroundedplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0027 Testing for URL Loading in WebViewsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0272 Identify Dependencies with Known Vulnerabilities in the Android Projectplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0002 Testing Local Storage for Input Validationplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0223 Stack Canaries Not Enabledplatform:androidprofile:L2newstatus:new
MASTG-TEST-0042 Checking for Weaknesses in Third Party Librariesplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0036 Testing Enforced Updatingplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0034 Testing Object Persistenceplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0044 Make Sure That Free Security Features Are Activatedplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0245 References to Platform Version APIsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0025 Testing for Injection Flawsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0222 Position Independent Code (PIC) Not Enabledplatform:androidprofile:L2newstatus:new
MASTG-TEST-0026 Testing Implicit Intentsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0043 Memory Corruption Bugsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0274 Dependencies with Known Vulnerabilities in the App's SBOMplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0283 Incorrect Implementation of Server Hostname Verificationplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0282 Unsafe Custom Trust Evaluationplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0295 GMS Security Provider Not Updatedplatform:androidprofile:L2newstatus:new
MASTG-TEST-0020 Testing the TLS Settingsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0022 Testing Custom Certificate Stores and Certificate Pinningplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0019 Testing Data Encryption on the Networkplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0235 Android App Configurations Allowing Cleartext Trafficplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0237 Cross-Platform Framework Configurations Allowing Cleartext Trafficplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0285 Outdated Android Version Allowing Trust in User-Provided CAsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0023 Testing the Security Providerplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0217 Insecure TLS Protocols Explicitly Allowed in Codeplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0236 Cleartext Traffic Observed on the Networkplatform:networkprofile:L1profile:L2newstatus:new
MASTG-TEST-0021 Testing Endpoint Identify Verificationplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0243 Expired Certificate Pins in the Network Security Configurationplatform:androidprofile:L2newstatus:new
MASTG-TEST-0242 Missing Certificate Pinning in Network Security Configurationplatform:androidprofile:L2newstatus:new
MASTG-TEST-0284 Incorrect SSL Error Handling in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0239 Using low-level APIs (e.g. Socket) to set up a custom HTTP connectionplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0244 Missing Certificate Pinning in Network Trafficplatform:networkprofile:L2newstatus:new
MASTG-TEST-0218 Insecure TLS Protocols in Network Trafficplatform:networkprofile:L1profile:L2newstatus:new
MASTG-TEST-0238 Runtime Use of Network APIs Transmitting Cleartext Trafficplatform:androidprofile:L1profile:L2placeholderstatus:placeholder
MASTG-TEST-0234 Missing Implementation of Server Hostname Verification with SSLSocketsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0286 Network Security Configuration Allowing Trust in User-Provided CAsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0233 Hardcoded HTTP URLsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0041 Testing for Debugging Code and Verbose Error Loggingplatform:androidprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0038 Making Sure that the App is Properly Signedplatform:androidprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0226 Debuggable Flag Enabled in the AndroidManifestplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0045 Testing Root Detectionplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0046 Testing Anti-Debugging Detectionplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0247 References to APIs for Detecting Secure Screen Lockplatform:androidprofile:L2newstatus:new
MASTG-TEST-0050 Testing Runtime Integrity Checksplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0249 Runtime Use of Secure Screen Lock Detection APIsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0288 Debugging Symbols in Native Binariesplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0051 Testing Obfuscationplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0048 Testing Reverse Engineering Tools Detectionplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0227 Debugging Enabled for WebViewsplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0047 Testing File Integrity Checksplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0224 Usage of Insecure Signature Versionplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0039 Testing whether the App is Debuggableplatform:androidprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0049 Testing Emulator Detectionplatform:androidprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0040 Testing for Debugging Symbolsplatform:androidprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0263 Logging of StrictMode Violationsplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0264 Runtime Use of StrictMode APIsplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0265 References to StrictMode APIsplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0225 Usage of Insecure Signature Key Sizeplatform:androidprofile:Rnewstatus:new
MASTG-TEST-0018 Testing Biometric Authenticationplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0017 Testing Confirm Credentialsplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0308 Runtime Use of Asymmetric Key Pairs Used For Multiple Purposesplatform:androidprofile:L2newstatus:new
MASTG-TEST-0014 Testing the Configuration of Cryptographic Standard Algorithmsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0221 Broken Symmetric Encryption Algorithmsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0212 Use of Hardcoded Cryptographic Keys in Codeplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0310 Runtime Use of Reused Initialization Vectors in Symmetric Encryptionplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0016 Testing Random Number Generationplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0015 Testing the Purposes of Keysplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0307 References to Asymmetric Key Pairs Used For Multiple Purposesplatform:androidprofile:L2newstatus:new
MASTG-TEST-0309 References to Reused Initialization Vectors in Symmetric Encryptionplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0312 References to Explicit Security Provider in Cryptographic APIsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0208 Insufficient Key Sizesplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0013 Testing Symmetric Cryptographyplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0205 Non-random Sources Usageplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0232 Broken Symmetric Encryption Modesplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0204 Insecure Random API Usageplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0314 Runtime Monitoring of Text Fields Eligible for Keyboard Cachingplatform:iosprofile:L2newstatus:new
MASTG-TEST-0060 Testing Memory for Sensitive Dataplatform:iosprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0301 Runtime Use of APIs for Storing Unencrypted Data in Private Storageplatform:iosprofile:L2newstatus:new
MASTG-TEST-0300 References to APIs for Storing Unencrypted Data in Private Storageplatform:iosprofile:L2newstatus:new
MASTG-TEST-0058 Testing Backups for Sensitive Dataplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0297 Insertion of Sensitive Data into Logsplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0215 Sensitive Data Not Marked For Backup Exclusionplatform:iosprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0053 Checking Logs for Sensitive Dataplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0313 References to APIs for Preventing Keyboard Caching of Text Fieldsplatform:iosprofile:L2newstatus:new
MASTG-TEST-0054 Determining Whether Sensitive Data Is Shared with Third Partiesplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0052 Testing Local Data Storageplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0303 References to APIs for Storing Unencrypted Data in Shared Storageplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0055 Finding Sensitive Data in the Keyboard Cacheplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0298 Runtime Monitoring of Files Eligible for Backupplatform:iosprofile:L1profile:L2profile:Pnewstatus:new
MASTG-TEST-0296 Sensitive Data Exposure Through Insecure Loggingplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0302 Sensitive Data Unencrypted in Private Storage Filesplatform:iosprofile:L2newstatus:new
MASTG-TEST-0299 Data Protection Classes for Files in Private Storageplatform:iosprofile:L1newstatus:new
MASTG-TEST-0281 Undeclared Known Tracking Domainsplatform:iosprofile:Pnewstatus:new
MASTG-TEST-0276 Use of the iOS General Pasteboardplatform:iosprofile:L2newstatus:new
MASTG-TEST-0279 Pasteboard Contents Not Expiringplatform:iosprofile:L2newstatus:new
MASTG-TEST-0069 Testing App Permissionsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0059 Testing Auto-Generated Screenshots for Sensitive Informationplatform:iosprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0072 Testing App Extensionsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0076 Testing iOS WebViewsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0278 Pasteboard Contents Not Cleared After Useplatform:iosprofile:L2newstatus:new
MASTG-TEST-0280 Pasteboard Contents Not Restricted to Local Deviceplatform:iosprofile:L2newstatus:new
MASTG-TEST-0057 Checking for Sensitive Data Disclosed Through the User Interfaceplatform:iosprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0070 Testing Universal Linksplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0075 Testing Custom URL Schemesplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0073 Testing UIPasteboardplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0056 Determining Whether Sensitive Data Is Exposed via IPC Mechanismsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0078 Determining Whether Native Methods Are Exposed Through WebViewsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0071 Testing UIActivity Sharingplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0277 Sensitive Data in the iOS General Pasteboard at Runtimeplatform:iosprofile:L2newstatus:new
MASTG-TEST-0290 Runtime Verification of Sensitive Content Exposure in Screenshots During App Backgroundingplatform:iosprofile:L2newstatus:new
MASTG-TEST-0077 Testing WebView Protocol Handlersplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0079 Testing Object Persistenceplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0229 Stack Canaries Not enabledplatform:iosprofile:L2newstatus:new
MASTG-TEST-0275 Dependencies with Known Vulnerabilities in the App's SBOMplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0273 Identify Dependencies with Known Vulnerabilities by Scanning Dependency Managers Artifactsplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0087 Make Sure That Free Security Features Are Activatedplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0085 Checking for Weaknesses in Third Party Librariesplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0080 Testing Enforced Updatingplatform:iosprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0230 Automatic Reference Counting (ARC) not enabledplatform:iosprofile:L2newstatus:new
MASTG-TEST-0086 Memory Corruption Bugsplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0228 Position Independent Code (PIC) not Enabledplatform:iosprofile:L2newstatus:new
MASTG-TEST-0067 Testing Endpoint Identity Verificationplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0068 Testing Custom Certificate Stores and Certificate Pinningplatform:iosprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0066 Testing the TLS Settingsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0065 Testing Data Encryption on the Networkplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0240 Jailbreak Detection in Codeplatform:iosprofile:Rnewstatus:new
MASTG-TEST-0088 Testing Jailbreak Detectionplatform:iosprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0246 Runtime Use of Secure Screen Lock Detection APIsplatform:iosprofile:L2newstatus:new
MASTG-TEST-0081 Making Sure that the App Is Properly Signedplatform:iosprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0084 Testing for Debugging Code and Verbose Error Loggingplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0093 Testing Obfuscationplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0248 References to APIs for Detecting Secure Screen Lockplatform:iosprofile:L2newstatus:new
MASTG-TEST-0092 Testing Emulator Detectionplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0082 Testing whether the App is Debuggableplatform:iosprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0090 Testing File Integrity Checksplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0083 Testing for Debugging Symbolsplatform:iosprofile:Rdeprecatedstatus:deprecated
MASTG-TEST-0261 Debuggable Entitlement Enabled in the entitlements.plistplatform:iosprofile:Rnewstatus:new
MASTG-TEST-0241 Runtime Use of Jailbreak Detection Techniquesplatform:iosprofile:Rnewstatus:new
MASTG-TEST-0219 Testing for Debugging Symbolsplatform:iosprofile:Rnewstatus:new
MASTG-TEST-0089 Testing Anti-Debugging Detectionplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0091 Testing Reverse Engineering Tools Detectionplatform:iosprofile:Rupdate-pendingstatus:update-pending
MASTG-TEST-0220 Usage of Outdated Code Signature Formatplatform:iosprofile:Rnewstatus:new
MASTG-TEST-0270 References to APIs Detecting Biometric Enrollment Changesplatform:iosprofile:L2newstatus:new
MASTG-TEST-0269 Runtime Use Of APIs Allowing Fallback to Non-Biometric Authenticationplatform:iosprofile:L2newstatus:new
MASTG-TEST-0268 References to APIs Allowing Fallback to Non-Biometric Authenticationplatform:iosprofile:L2newstatus:new
MASTG-TEST-0064 Testing Biometric Authenticationplatform:iosprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0266 References to APIs for Event-Bound Biometric Authenticationplatform:iosprofile:L2newstatus:new
MASTG-TEST-0271 Runtime Use Of APIs Detecting Biometric Enrollment Changesplatform:iosprofile:L2newstatus:new
MASTG-TEST-0267 Runtime Use Of Event-Bound Biometric Authenticationplatform:iosprofile:L2newstatus:new
MASTG-TEST-0211 Broken Hashing Algorithmsplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0209 Insufficient Key Sizesplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0213 Use of Hardcoded Cryptographic Keys in Codeplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0210 Broken Symmetric Encryption Algorithmsplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0317 Broken Symmetric Encryption Modesplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0062 Testing Key Managementplatform:iosprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0214 Hardcoded Cryptographic Keys in Filesplatform:iosprofile:L1profile:L2newstatus:new
MASTG-TEST-0063 Testing Random Number Generationplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0061 Verifying the Configuration of Cryptographic Standard Algorithmsplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0311 Insecure Random API Usageplatform:iosprofile:L1profile:L2newstatus:new



[8]ページ先頭

©2009-2025 Movatter.jp