Technical details
Logical testing: review of APK/IPA packages, APIs, and SDKs; validation of storage, authentication, communications, and log exposure.
Physical testing: magnetic stripe reader testing, HID/BadUSB attacks, brute-force attacks against configurations, kiosk mode bypass, network access through USB-C, Wi-Fi analysis during payment processes, ADB/Logcat controls, and automated payment attacks via HID.
Business approach
Protects transactions and sensitive POS data, helping prevent fraud and data leakage while supporting compliance with financial and payment industry regulations.
Deliverables
- ✅ Technical vulnerability report
- ✅ OWASP Mobile Top 10 classification
- ✅ PCI DSS mapping
- ✅ Exploitation evidence
- ✅ Remediation guide