40% of Android apps expose sensitive back end information
codifiedsecurity.com
40% of Android apps expose sensitive back end information
1–5 of 5 posts
Re: 40% of Android apps expose sensitive back end information
#2Interesting stuff, what was the methodology behind this?
Re: 40% of Android apps expose sensitive back end information
#3Interesting stuff, what was the methodology behind this?
We grabbed a selection of 2,000 top apps from the UK Play Store that were built in Java.
We looked for strings that matched certain entropy patterns common to the services listed on the site.
For staging environments we looked at likely candidates from string variable names and patterns that looked likely to be staging environments.
It's really dreadful the amount of debug/useless code that gets left in production Android apps, and it tends to grow over time.
Re: 40% of Android apps expose sensitive back end information
#4Finance apps?
Re: 40% of Android apps expose sensitive back end information
#5Finance apps?
Some finance apps included development/staging details, yes. We didn't find any secrets from traditional finance firms (I expect this is more a function of them not using cloud services as much as other industries at this point in time).
One of the worst offenders in our sample was fintech companies, with obviously no real pentesting being done on the client side at least.