Server level

At the server level, the entire web server and web service communications are applicable. The following figure gives the high-level mind map for the set of important sections that have to be tightened before providing the backend services to any given mobile app. It also has the mapping done with the OWASP 10 (https://www.owasp.org/index.php/Top_10_2013-Top_10), which are applicable. The server will not be considered completely secure with the following recommendations; however, developers have to refer to the OWASP Application Security Verification Standards for web apps.

Server level

Authentication

The majority of apps in the app store have not ...

Get Mobile Application Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.