Reader small image

You're reading from  Mobile Application Penetration Testing

Product typeBook
Published inMar 2016
Reading LevelIntermediate
PublisherPackt
ISBN-139781785883378
Edition1st Edition
Languages
Tools
Right arrow
Author (1)
Vijay Kumar Velu
Vijay Kumar Velu
author image
Vijay Kumar Velu

Vijay Kumar Velu is a passionate information security practitioner, author, speaker, investor, and blogger. He has 16+ years of IT industry experience, is a licensed penetration tester and is specialized in providing technical solutions to diverse cyber problems, ranging from simple security configuration reviews to cyber threat intelligence. Vijay holds multiple security qualifications, including CEH, ECSA, and CHFI. He has authored a few books on penetration testing: Mastering Kali Linux for Advanced Penetration Testing – Second & Third Editions, and Mobile Application Penetration Testing. For the community, Vijay serves as the chair member of NCDRC, India. When not working, he enjoys playing music and doing charity work.
Read more about Vijay Kumar Velu

Right arrow

Snoop-IT for assessment


Snoop-IT runs only on the 32-bit architecture. This has significantly limited the tool to be utilized in latest mobile phones. However, a majority of the tasks that we performed manually in the preceding sections can be performed by this single tool. The following screen capture of Snoop-it displays the filesystem during the runtime of this app.

Typically, there are three sections:

  • Monitoring: Monitor the filesystem, keychain, network, sensitive APIs, and common cryptography used

  • Analysis: This section displays all the objective-C classes, controllers, and other URL schemes

  • Runtime manipulation: Unlike Cycript, which we perform manually, this is just a single-click manipulation that one can perform in the GUI environment

Once we have a 64-bit version of Snoop-IT available, it will be one of the best tools to be used for any iOS app security assessment. Other tools, such as Appsec labs iNalyzer (https://github.com/appsec-labs/iNalyzer) and Veracode's iRET (https://www...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Mobile Application Penetration Testing
Published in: Mar 2016Publisher: PacktISBN-13: 9781785883378

Author (1)

author image
Vijay Kumar Velu

Vijay Kumar Velu is a passionate information security practitioner, author, speaker, investor, and blogger. He has 16+ years of IT industry experience, is a licensed penetration tester and is specialized in providing technical solutions to diverse cyber problems, ranging from simple security configuration reviews to cyber threat intelligence. Vijay holds multiple security qualifications, including CEH, ECSA, and CHFI. He has authored a few books on penetration testing: Mastering Kali Linux for Advanced Penetration Testing – Second & Third Editions, and Mobile Application Penetration Testing. For the community, Vijay serves as the chair member of NCDRC, India. When not working, he enjoys playing music and doing charity work.
Read more about Vijay Kumar Velu