January 19, 2022

Under the Sheets, Practical Android Static Analysis

In this blog, the topic of Android client-side controls is discussed. Client-side controls are a topic of controversy with the Mobile Security industry, in almost all cases providing only a layer of obscurity between an attacker and potentially sensitive functionality. The aim of this piece is to demonstrate how this may be exploited during a Penetration test and why such controls are inherently vulnerable to interference from an attacker.

