Network |
Certificate pinning |
|
Weak Cipher |
|
API to negotiated with SSL |
|
Leak Info via Side Channel |
|
Improper Usage of HTTP Method |
|
|
Server |
Authentication |
|
Injection |
|
Session Management Issues |
|
Server banners |
|
|
Device |
Insecure Data Storage (log, database, keychain, NSUserDefaults, cache, etc) |
|
JavaScript Execution(Webview) |
|
Code Quality (codesign , debug symbol,free security features, etc ..) |
|
Anti-reversing Detection(jailbreak/root detection, File integrity , Device Bonding ) |
请发表评论