MASTG walkthrough - OMTG_DATAST_001_SharedPreferences

The intent here is to show that no sensitive information should be stored in Shared Preferences as it is stored by default in clear text.

datast_001_shr_1

Take a look at the source code

datast_001_shr_2

Line 22 indicates that we should look for a file called “key.xml” in /data/data/sg.vp.owasp_mobile.omtg_android/shared_prefs folder.

datast_001_shr_3

Tools used

Thoughts? Leave a comment