Request for feedback on Android exported ContentProvider lab finding #3788
Closed
kmerghlani
started this conversation in
General
Replies: 1 comment
|
Hi @kmerghlani. The MASTG discussions are intended for questions and contributions related to the project itself, around the test cases, techniques, weaknesses etc. We're not able to review individual findings, validate "evidence grade", or advise on how a specific result should be presented in a report. That falls outside the project's scope. The MASTG covers already ContentProvider security in detail (it is currently re-worked and will be updated soon), the weakness, applicable tests and the resources you need are already there. How you apply them to a specific engagement is the tester's call. Closing this as out of scope for project discussions. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi everyone,
I’m building my mobile/API security evidence discipline and would appreciate quick feedback on one Android lab finding.
Finding:
Exported Android ContentProvider allows external insertion of notes.
Context:
This is from DIVA, an intentionally vulnerable Android lab app. No real client app, production app, or user data is involved.
Evidence chain:
What I’m trying to validate:
I prepared a small review packet with the finding card, evidence manifest, command outputs, and smali excerpt. I can share the relevant text here or a sanitized ZIP if appropriate.
Thanks,
Khaled
All reactions