Author
Ostorlab Team
Finding security bugs in Android applications the hard way
Ostorlab is a community effort to build a mobile application vulnerability scanner to help developers build secure mobile applications. One of the new key components of the scanner detection capabilities is a new shiny static taint engine for Android Dalvik Bytecode that was heavily optimized for performance and low false positives.
Jun 16, 2017
June 2017
We are pleased to announce a set of new improvements
Jun 01, 2017
New Taint Engine ... more vulnerabilities found
We have been for the last few months hard at work developing a new scan engine to identify new cl...
Apr 23, 2017
Testing Cordova Applications
Hybrid frameworks like Cordova offers the advantage of building one app for multiple platform (su...
Nov 24, 2016
More by Ostorlab Team
Android, SQL and ContentProviders or Why SQL injections aren't dead yet ?
Before we get into SQL injections and what might go wrong, we'll start by covering some technical information on Content Providers...
Nov 03, 2016
Android external libs!
For an Android developer, it has become standard practice to use external libraries to easily extend the functionalities of the mobile application . Thanks to Gradle easy dependency integration, features like HTTP frameworks, database ORM, fancy scrolling, efficient image loading, caching, social network integration and many others can be added easily.
Nov 01, 2016
Vulnerabilities tested by Google Play Store
Google will start identifying security weaknesses in Apps pushed to the Play Store...
Sep 05, 2016
Python ProcessPoolExecutor: A Custom Process Pool
At Ostorlab we scan hundreds of Mobile Applications each day, each scan is very resource intensive but at the same time, since the beginning, we had to optimize the code for speed and maximize use of cloud resources.
Jul 18, 2016
New in Android M and N: Runtime Permissions
In Android, the permission system was one of the major security concerns of the platform for many reasons...
May 27, 2016
What Is SSL Pinning? Android Guide with OkHttp
Implement SSL pinning on Android with Network Security Config, OkHttp and Retrofit, then test it and rotate pins safely. Includes legacy library examples.
May 11, 2016
Reversing JNI, or how Facebook is crashing their own application
Apparently Facebook is crashing their apps intentionally in order to test users reaction and evaluate their adherence to Facebook service. This post is however not about the user's behavioral analysis, but about the technical aspects of how it is done - or just an excuse to dive into JNI reversing.
Jan 07, 2016
What every pentesters should learn in 2016
The last years have come with meaningful changes in the way IT professionals operate and the way we approach security...
Jan 02, 2016
Ostorlab Beta is out
We are pleased to release the Beta version of our online mobile application security scanner.
Dec 20, 2015
Best SSL/TLS resources (Attacks, Tools, Talks)
This article will reference the best current resources on SSL/TLS.
Aug 25, 2015