Pentest on an Internet Mobile App: A Case Study using Tramonto
Daniel Dalalana Bertoglio, Guilherme Girotto, Charles Varlei Neu, and Roben Castagna Lunardi, and Avelino Francisco Zorzo

TL;DR
This paper demonstrates how the Tramonto framework can be effectively used to perform a structured and efficient penetration test on a mobile application, revealing vulnerabilities and improving security assessment practices.
Contribution
It provides a detailed case study applying the Tramonto framework to a real mobile app, showcasing its benefits in organizing and optimizing Pentest processes.
Findings
Identified multiple security vulnerabilities in the mobile app.
Showed Tramonto's effectiveness in organizing Pentest activities.
Enhanced understanding of security assessment workflows.
Abstract
Mobile applications are used to handle different types of data. Commonly, there is a set of personal identifiable information present in the data stored, shared and used by these applications. From that, attackers can try to exploit the mobile application in order to obtain or to cause private data leakage. Therefore, performing security assessments is an important practice to find vulnerabilities in the applications and systems before the application is deployed, or even during their use. Regarding security assessments, Penetration Test (Pentest) is one of the security test types that can be used to detect vulnerabilities through simulated attacks. Additionally, Pentest can be performed using different methodologies and best practices, through several frameworks to: organize the test execution, execute tools, provide estimations, provide reports and document a Pentest. One such…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
