I will do mobile app penetration testing for android and ios
Senior Red Team Operator and Penetration Tester OSCP, OSEP, CRTO
Level 2
Has met high performance criteria and has a proven track record for meeting client expectations.
About this Gig
Mobile apps leak secrets, store data unsafely, and trust the device too much. I find all of it.
Senior pentester (OSCP, OSEP, OSWE) testing Android and iOS apps against the OWASP MASVS/MASTG standard. This covers the app, the device storage, and the backend API the app talks to.
What I test:
- Hardcoded secrets, API keys, and tokens in the build
- Insecure local storage, weak crypto, and exported component abuse
- SSL pinning and root/jailbreak detection bypass to inspect live traffic
- Deeplink and WebView abuse, plus the backend APIs (IDOR, auth, injection)
What you get:
- A professional report with severity, CVSS, decompiled proof, and exact remediation
- Executive summary plus a developer technical section
- One free retest after you patch
Send me the APK/IPA (or store link) and a test account. I will scope it and give you a fixed quote before you order.
Device:
Desktop
•
Laptop
•
Server
•
Mobile
•
Tablet
Operating system:
Windows
•
Linux
•
Unix
•
Android
•
Ubuntu
FAQ
Do you need source code?
No, I work from the compiled app. Source is optional and deepens coverage.
Flutter or React Native apps?
Yes, including pinning bypass for Flutter.

