Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Swaroop Yermalkar -- iGoat and iOS Mobile Pen Testing

28 min13 november 2018

Om avsnittet

Mobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes. OWASP iGoat project leader Swaroop Yermalkar joins Chris to explain how he approaches testing iOS and Swift applications, starting with understanding the business and following the data. They discuss hardcoded cloud keys, inspecting application classes, proxying traffic, and weaknesses in mobile service endpoints. Swaroop then introduces iGoat as a practical learning environment where people can exploit a flaw, understand the remediation, and rebuild the application with a fix. A cloud-storage exercise illustrates how client-side clues lead to a wider exposure. The episode closes with iGoat’s relationship to OWASP’s mobile guidance and why these skills matter across Apple’s expanding device ecosystem.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Swaroop Yermalkar:
Swaroop Yermalkar on LinkedIn
OWASP iGoat

Mentioned in this episode:
iGoat Swift
OWASP Mobile Application Security Testing Guide
Burp Suite
OWASP WebGoat

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 iOS security and iGoat with Swaroop Yermalkar
01:11 From Wi-Fi curiosity to application security
02:42 Mobile applications in bug bounty programs
03:44 Testing Swift applications
05:01 Hardcoded keys and excessive permissions
07:45 Understanding the business before testing
10:51 Inspecting and decrypting an iOS application
12:24 Static analysis and proxying mobile traffic
13:58 Why mobile backends deserve attention
15:53 What the iGoat learning environment contains
17:57 Fixing the vulnerability after exploiting it
19:13 A cloud-storage misconfiguration exercise
23:18 Future directions and new challenges
24:49 Connecting iGoat with OWASP mobile standards
26:24 Applying the skills across devices

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.