Mobile Penetration Testing Android & iOS
Budget: $10 – $30 USD
I need a thorough penetration test focused exclusively on phones, with coverage for both Android and iOS devices. The goal is to identify real-world attack paths, verify exploitability, and provide clear, actionable remediation guidance. I expect you to approach this as a black-box engagement that mirrors an external attacker’s perspective, diving into areas such as code weaknesses, insecure storage, improper platform usage, and over-permissive network calls.
Please plan to use industry-standard tooling and methodology—think OWASP Mobile Top 10 checks with MobSF, dynamic analysis through Burp Suite or mitmproxy, runtime instrumentation via Frida, and network traffic inspection with Wireshark—while documenting every finding with proof of concept evidence and reproducible steps.
Deliverables should include:
• A concise executive summary for non-technical stakeholders
• A detailed technical report (vulnerabilities, risk ratings, reproduction steps, and mitigation advice)
• A debrief call or walkthrough to clarify findings and next steps
Schedule is flexible, but I’d like an estimated timeline up front along with any device, build, or provisioning needs you have so we can get started quickly.
Please plan to use industry-standard tooling and methodology—think OWASP Mobile Top 10 checks with MobSF, dynamic analysis through Burp Suite or mitmproxy, runtime instrumentation via Frida, and network traffic inspection with Wireshark—while documenting every finding with proof of concept evidence and reproducible steps.
Deliverables should include:
• A concise executive summary for non-technical stakeholders
• A detailed technical report (vulnerabilities, risk ratings, reproduction steps, and mitigation advice)
• A debrief call or walkthrough to clarify findings and next steps
Schedule is flexible, but I’d like an estimated timeline up front along with any device, build, or provisioning needs you have so we can get started quickly.