Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

How the Latest MASVS and MSTG Specs Enhance Mobile Penetration Testing

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course reviews how changes to OWASP’s MASVS and MSTG shape mobile application security testing. It covers mobile attack surfaces, sensitive data, client-side controls, network testing, authentication, and security practices in the software development lifecycle.

Syllabus

Intro
Mobile Powers the World, But Mobile Risk is Pervasive
Mobile Security Challenges by the Numbers
Web & Mobile are Fundamentally Different
Understand the Mobile Attack Surface
Understand the Anatomy of a Mobile Attack
Get started on the right path
Leverage OWASP Mobile Project
Use all Your Senses
Learn the Mobile Attack Surface
Changes in MASVS - Platform Interaction
Sensitive data leaks like an overfilled drink
Changes in MASVS - Data Storage
Don't cringe at client-side security controls
Test network on mobile
Don't water down auth & session mgmt
The order matters: Test first, then resilience
Framework for Setting Policy
Don't mix up Security & Privacy, Not the Same
The flavor palate varies widely
Buy a dev a drink, and they might buy you one too
Tony's Mobile Top Ten Recipe
Summary Recommendations
A Sampling of OSS Tools
Leverage Mobile AppSec Testing Checklist
Build Security Into Your SDLC

Taught by

OWASP Foundation

Reviews

Start your review of How the Latest MASVS and MSTG Specs Enhance Mobile Penetration Testing

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.