-
-
Notifications
You must be signed in to change notification settings - Fork 2.7k
Description
Create a new MASTG v2 test covering for:
- Title: Testing for Overlay Attacks
- ID: MASTG-TEST-0035
- Link: https://mas.owasp.org/MASTG/tests/android/MASVS-PLATFORM/MASTG-TEST-0035/
- Platform: android
- MASVS v1: ['MSTG-PLATFORM-9']
- MASVS v2: ['MASVS-PLATFORM-3']
Focus on static analysis and ignore the dynamic analysis section in the old MASTG-TEST-0035.
Create also:
- a demo in demos/
- a best practice in best-practices/
Follow the guidelines in .github/instructions/porting-mastg-v1-tests-to-v2.instructions.md as well as other .github/instructions/
References:
- https://developer.android.com/privacy-and-security/risks/tapjacking
- https://mas.owasp.org/MASTG/knowledge/android/MASVS-PLATFORM/MASTG-KNOW-0022/ (link this to the test as
knowledge: [MASTG-KNOW-0022]and update the knowledge if needed)
Reactions are currently unavailable