Mobile › Module 7 › Lesson 2
MASTG Named
OWASP MASTG literacy — test case IDs, evidence rows, and defender verification workflow on $MOB_LAB.
Visual · t27_mastg_named
MASTG = named testing guide. Evidence-backed. $MOB_LAB. Original Cyberlium.
Opening
MASTG turns MASVS into test cases — cite test IDs and evidence from YOUR lab app, not from hacking apps you do not own.
MASTG (Mobile Application Security Testing Guide) literacy: test cases map to MASVS controls — MASTG-TEST-XXXX IDs, platform chapters (Android/iOS), static vs dynamic vs network test classes, evidence expectations (screenshot, log snippet, code reference) with observed vs inferred separation. Defenders use MASTG for repeatable verification and dev retest — purple teams align purple findings to MASTG rows. Cyberlium on $MOB_LAB: pick three MASTG test IDs relevant to your lab app, draft evidence row stubs — NOT full unauthorized dynamic bypass suites on production, NOT SSL-pinning bypass cookbooks for apps you do not own (Module 5 refused). Output: MASTG-ID ↔ MASVS-ID mapping table with evidence column.
1. MASTG structure
Test IDs link to MASVS controls — static, dynamic, network, reverse engineering chapters at literacy level.
Evidence row: ID, steps summary (no exploit cookbook), result, observed artifact path on $MOB_LAB.
Command guide
Try these commands — MASTG structure
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
OWASP MASTG — https://mas.owasp.org/MASTG/ (mobile testing guide) MASTG GitHub — https://github.com/OWASP/MASTG (portable continuum / repo literacy) OWASP MSTG apps — https://mas.owasp.org/MASTG/0x04b-Mobile-App-Authentication/ (sample apps)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export MOB_LAB=${MOB_LAB:-$HOME/cyberlium-lab/t27-mob}
curl -sS https://mas.owasp.org/MASTG/ | head -10
curl -sS https://github.com/OWASP/MASTG | head -8
grep targets "$MOB_LAB/roe.txt"Primary tools to practice this lesson: curl, grep. Reference sites: OWASP MASTG (https://mas.owasp.org/MASTG/); MASTG GitHub (https://github.com/OWASP/MASTG); OWASP MSTG apps (https://mas.owasp.org/MASTG/0x04b-Mobile-App-Authentication/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Defender verification
Retest closes MASTG-ID with before/after evidence — dev-friendly handoff.
Inferred impact labeled — do not collapse into observed bullet.
3. Refused
No MASTG execution on unauthorized targets; no pinning bypass recipes for stranger apps.
MASTG supports verification — not illegal circumvention of protections.
4. What you ship: MASTG mapping table
Three MASTG-ID rows + MASVS link + evidence column + scope line.
5. What you record before the next lesson
MASTG mapping table path.
6. Wrong vs right: stranger phones vs lab emulator apps
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Run MASTG dynamic bypass suite on employer production app without RoE.
Right
MASTG mapping table from $MOB_LAB. Next: Secure Coding Mobile.
Mission: MASTG mapping table
1) Define MASTG vs MASVS in one line each. 2) Three MASTG-ID rows with evidence stubs. 3) Observed vs inferred column. 4) Write NEVER unauthorized target line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Static vs dynamic MASTG — minimum evidence?”
Knowledge Check
APPLY: MASTG provides:
Multiple choice
Knowledge Check
APPLY: True or False: MASTG on unauthorized prod app is lab.
True or False
Knowledge Check
APPLY: MASTG evidence rows should:
Multiple choice