The market share of Windows Phone devices continues to grow and so grows the number of WP applications: from simple games and social apps to complex business apps. WP security model is considered to be secure; nevertheless, the application themselves may have potential vulnerabilities. In this presentation, we want to show the techniques we use to analyze the security of WP applications. We will introduce a new tool that makes analysis much easier. This tools allows using both static and dynamic (code instrumentation) techniques. In fact, it is an environment for WP application analysis. We will also show on real examples how to find vulnerabilities with this tool and exploit them.
Видео выступления на BH отсутствует, но есть видео, которое является логическим продолжением
HIP13 : Windows Phone 8 application security
Windows Phone 8 is a new mobile platform and there is not so much information about security issues out there. This presentation will cover Windows Phone 8 security model. We will especially cover applications security. During our research we examined number of Windows Phone applications and learned where developers have to be careful when developing applications and where auditors may find vulnerabilities. Application analysis requires number of tools, from generic tools like disassembler to more specific tools like .NET decompiler. There are few tools targeting Windows Phone 7 platform and applications, offering some features like decompiling, logging method calls and deploying app to Windows Phone emulator. But all of these features are basic and does not offer a lot, and none of these tools support Windows Phone 8 applications. During our work we created a tool that makes application analysis easier.
Слайды в комментариях
