
OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar
Select the OWASP iGoat Version:
iGoat (Objective C) was presented at:
iGoat is a learning tool for iOS developers (iPhone, iPad, etc.) and mobile app pentesters. It was inspired by the WebGoat project, and has a similar conceptual flow to it.
As such, iGoat is a safe environment where iOS developers can learn about the major security pitfalls they face as well as how to avoid them. It is made up of a series of lessons that each teach a single (but vital) security lesson.
Step 4 is optional, but highly recommended for all iOS developers. Assistance is available within iGoat if you don't know how to fix a specific problem.
Page - https://www.owasp.org/index.php/OWASP_iGoat_Tool_Project
Project Lead - Swaroop Yermalkar (@swaroopsy)
Twitter - (@OWASPiGoat)
Lead Developer - Anthony Gonsalves
Key Management
URL Scheme Attack
Social Engineering
Reverse Engineering
Data Protection (Rest)
Data Protection (Transit)
Authentication
Side Channel Data Leaks
Tampering
Injection Flaws
Broken Cryptography
To contribute to iGoat project, please contact Swaroop ( [email protected] or @swaroopsy )