STATIC CODE ANALYSIS RESULT
SOURCE:
TOTAL FILES:
JAVA FILES:
A View that displays web pages. This class is the basis upon which you can roll your own web browser or simply display some online content within your Activity. It uses the WebKit rendering engine to display web pages and includes methods to navigate forward and backward through a history, zoom in and out, perform text searches and more. WebViews may be implemented using the "Android/AOSP" (WebViewClient) or Chrome (WebChromeClient) browsers.
This is a list of all the findings related to Certificate validation.
This section lists any issues related to File permissions.
This section lists any issues related to pending intents.
This section lists any issues related to crypto vulnerabilities in the application
Until we perfect this, for manually testing, run the following command to see all the options and their meanings: adb shell am . Make sure to update qark frequently to get all the enhancements! You'll also find some good examples here: http://xgouchet.fr/android/index.php?article42/launch-intents-using-adb
Until we perfect this, please review these files manually. Due to parsing errors, it is possible that an issue may not have been reported correctly.
This section is related to any operating system related issues. This information was identified from the application's manifest and we encourage you to understand the type of vulnerabilities that live ourside your application's sandbox but may affect your application in some way or the other.
OS Version specific bugs
Plugin content output if any
This is a list of resources you may refer to understand more about android security in general and also how specific programming mistakes or insecure-by-default settings may manifest themselves into vulnerabilities. We are currently hand picking credible resources to add to the list. Please check for updates to get a revised list of references.
List of resources
For general Android security information: http://developer.android.com/training/articles/security-tips.html
- For information on proper TLS implementation: http://developer.android.com/training/articles/security-ssl.html
- A great guide to Android security, from the Japanese Smartphone Security Association: https://www.jssec.org/report/android_securecoding_en_20140801.html
QUICK ANDROID REVIEW KIT
Version 0.9Source:
Github: https://www.github.com/linkedin/qark
Authors:
Anthony Trummer: https://www.linkedin.com/in/tonytrummerTushar Dalvi: https://www.linkedin.com/in/tdalvi
QARK Version 0.9