Chapter 6: Web Server Attacks

Most mobile apps that do real work will in some way connect to a back-end web server. If the communication is via a web service, this can either be via SOAP or, more commonly, by using a REST web service. In this chapter it’s a case of what’s old is new again. We’ll explore how the same security best practices that have applied to web servers for the past 20 years apply to web servers used in mobile apps. We’ll also look at how we can use logins from other website break-ins to help secure our authentication.

Get Bulletproof Android™: Practical Advice for Building Secure Apps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.