Here we have collected a list of articles which can help beginners to start learning android security.
Before starting with Learning android specific Security issues it would make sense to start with some generic approach and hence its best suited to start with learning about OWASP Mobile Security Project and OWASP Mobile security Top 10
To further dig deep in Android Specific sections Here i am listed multiple sources which can be referred and used to understand Android Security.
(I have listed all articles which would be helpful however some of the tools listed in them may not run in Android Tamer due to architectural limitation).
You can find various presentations i have made aroundAndroidTamer listed here
I have personally been taking session on OWASP Mobile Top 10 at Null Banagalore Chapter Meets Here i have listed the slides that i have created for those purposes.
This is still not finished and slides will be added around the other sections of the OWASP Mobile top 10.
A 4 part series by Prateek Gyanchandani on Android application Pentesting using insecure Bank
A fellow researcher Srinivas has written multiple articles at Info Sec Institute using Android Tamer Here are a list of those articles.
- Cracking DIVA Part – 1
- Cracking DIVA Part – 2
- Cracking DIVA Part – 3
- Cracking DIVA Part – 4
- Cracking DIVA Part – 5
- Android Tamer : A Walk-through
- Introduction to Android Forensics
- Part 1
- Part 2
- Part 3
- Part 4
- Part 5
- Part 6
- Part 7
- Part 8
- Part 9
- Part 10
- Part 11
- Part 12
- Part 13
- Part 14
- Part 15
- Part 16
Another Fellow Researcher Aditya Agrawal is working on series of Android Security related articles, Linked below.
- Android Application Security Part 1- Setup Mobile Pentesting Platform
- Android Application Security Part 2- Understanding Android Operating System
- Android Application Security Part 3- Android Application Fundamentals
- Android Application Security Part 3- – Get to know about your Arsenals
- Android Application Security Part 5 – Drozer
- Android Application Security Part 6-Let the Fun Begin
- Android Application Security Part 7-Understanding AndroidManifest.xml File
- Android Application Security Part 8 – Insecure Data Storage
- Android Application Security Part 9 – Binary Protections
- Android Application Security Part 10 – Insufficient Transport Layer Protection
- Android Application Security Part 11 – Unintended Data Leakage
- Android Application Security Part 12 – Poor Authentication And Authorization
- Android Application Security Part 13 – Broken Cryptography
- Android Application Security Part 14 – Security Decisions via Untrusted Input
- Android Application Security Part 15 – Attacking Content Providers
- Android Application Security Part 16 – Attacking Services
- Android Application Security Part 17 – Attacking Activities
- Android Application Security Part 18 – Attacking Broadcast Receivers
- Android Application Security Part 19 – Improper Session Handling
- Android Application Security Part 20 – Client Side Injections
- Android Application Security Part 21 – Exploiting Debuggable Applications
- Android Application Security Part 22 – Developer Backdoor
- Android Application Security Part 23 – Spoofing your location in Play Store
- Android Application Security Part 24 – Configuring your Device for Pentesting
- Android Application Security Part 25 – Install Google Play Store in Genymotion
- Android Application Security Part 26 – Intercept Traffic on Android version after 4.2.2
Do suggest if you feel some other beginner friendly resources are being missed out here. Add your contributions via comment form and we will add you as a contributor on this page.
Thanks Anant for such awesome collection on android stuffs !!
Surely will try these learning up all 🙂
Thanks for your brilliant effort . It is really helpful.
Its just awesome! For a beginner to kick start with android security testing will definitely helps a lot.
Thank you so much..
Wow! what a article,it’s just awesome. I was looking for the same and I got everything in one shot here..
I did not know such a great article on android securiyt existed. Great job.