Skip to content
normSight — Cyber Security

Solutions

Mobile Application Penetration Testing

Mobile application penetration testing identifies security flaws in what an iOS or Android application stores on the device, how it communicates with the server, and in its back-end APIs.

Advancing technology has made the internet usable on mobile systems, that is on smartphones and tablets. Companies and institutions have therefore had to adapt their web systems to work on mobile devices. In that situation, just as with an ordinary web application, mobile application penetration testing must also be carried out on mobile applications.

Mobile applications today help you communicate quickly with customers and work more easily. However, because these applications are critically important, a wide range of attacks can be carried out against them, creating dangerous situations both for the organisation and for its customers.

The mobile application used by any brand or company is a structure in which data is stored, interaction takes place, communication is carried out and customer information is held. Mobile application penetration testing is therefore critically important and must be applied reliably. During an attack on a mobile application, malicious actors may view documents, reach company information, halt services, obtain unintended user information and cause problems such as blocking web pages.

Against all the risks you may face, mobile application penetration testing first uses a reconnaissance method; the information obtained is then used to assess the system’s entry points and weaknesses. The identified weak points are then used to enter the system, an attack is carried out within the framework of a simulation, and a report is produced. In this way every threat the mobile application may face is uncovered and remediation methods are sought.

Frequently Asked Questions

How does mobile testing differ from web testing?

With a mobile application an attacker may have physical access to the device. Data the application stores locally, keys embedded in the code, certificate pinning and resilience to reverse engineering are therefore tested in addition.

Are the back-end APIs also in scope?

Yes, and including them is critical. A significant share of serious findings in mobile applications appears not in the app itself but in back-end APIs that perform insufficient authorisation.

Is the released version of the app tested?

Either the released version or a pre-release build can be tested. Pre-release testing is preferable, because the flaws found are fixed before the app reaches the store.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.