DVIA - Damn Vulnerable iOS Application
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable.
Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment.
This application covers all the common vulnerabilities found in iOS applications (following OWASP top 10 mobile risks) and contains several challenges that the user can try. It also contains a section where a user can read various articles on iOS application security.
Vulnerabilities and Challenges in the DVIA:
- Insecure Data Storage
- Extension Vulnerabilities
- Attacks on third party libraries
- Jailbreak Detection
- Runtime Manipulation
- Piracy Detection
- Sensitive information in memory
- Transport Layer Security (http, https, cert pinning)
- Client Side Injection
- Information Disclosure
- Broken Cryptography
- Security Decisions via Untrusted input
- Side channel data leakage
- Application Patching
All these vulnerabilities and their solutions have been tested up to iOS 10.
Here is a video tutorial on How to get started with Damn Vulnerable iOS App:
You might also like:
from Effect Hacking full article here