Introduction
We express our gratitude to the Bit2Me team for the collaborative engagement that enabled the execution of this Security Assessment.
| title | content |
|---|---|
| Platform | iOS, Android |
| Timeline | 3 Jan 2024 - 19 Jan 2024 |
Audit Summary
10/10
\-
\-
\-
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Mobile Application Penetration Test Report for Bit2me |
| Audited By | Ece Orsel |
| Approved By | Stephen Ajayi |
| Website | https://bit2me.com→ |
| Changelog | 29/02/2024 - Final Report |
Document
- Name
- Mobile Application Penetration Test Report for Bit2me
- Audited By
- Ece Orsel
- Approved By
- Stephen Ajayi
- Website
- https://bit2me.com→
- Changelog
- 29/02/2024 - Final Report
System Overview
The following table provides a synopsis of target systems that were within the scope of this Security Assessment.
Bit2Me Mobile Application: iOS, Android
Executive Summary
Security score
Upon auditing, the code was found to contain 0 critical, 0 high, 0 medium, and 6 low severity issues, leading to a security score of 10 out of 10. After the completion of the remediation check, the status of the previously identified security vulnerabilities is as follows: 1 low severity vulnerabilities were accepted. 6 low severity and one informational severity vulnerability were successfully fixed.
All identified issues are detailed in the “Findings” section of this report.
Summary
The overall rating of Customer Applications, after the security assessment by the Consultant’s Security Team, stands out to be 10 out of 10. The security assessment was carried out following the in-house test cases, manual methods, exploitation, and automated tools.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-0533 | Input fields with sensitive data should be cleared after hiding/opening the application | fixed | Low | |
| F-2024-0528 | Application Vulnerable to Janus Vulnerability | fixed | Low | |
| F-2024-0527 | Missing Security Headers | fixed | Low | |
| F-2024-0526 | Application Running in Emulator | fixed | Low | |
| F-2024-0525 | Lack of Obfuscation or Encryption in Code | fixed | Low | |
| F-2024-0523 | Insecure Storage of Sensitive Data in NSUserDefaults | accepted | Low | |
| F-2024-0532 | Use of Malloc Function Leading to Uncontrolled Memory Allocation | fixed | Observation | |
| F-2024-0531 | Use of Insecure API(s) in Application Binary | accepted | Observation | |
| F-2024-0529 | Unprotected Service Accessible to Other Applications | accepted | Observation | |
| F-2024-0524 | Exposure of Unique Identifiers | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following :
Scope Details | |
|---|---|
| Mobile Application | Android and iOS→ |
| API | Not Required |
| Whitepaper | Not Required |
| Requirements | Not Required |
| Technical Requirements | Not Required |
Scope Details
- Mobile Application
- Android and iOS→
- API
- Not Required
- Whitepaper
- Not Required
- Requirements
- Not Required
- Technical Requirements
- Not Required