How to Hack & Protect Flutter Apps — Steal Firebase Auth token and attack the API. (Pt. 3/3)

First things first. JSON web tokens.

Firebase Authentication


How to steal Firebase authentication token
Step 1: Demo app



Step 2: Extraction of JWT






Attack the API
How to do API attacks in a nutshell
Discover API architecture from Flutter app
Actionable steps for app owners
Resources
Latest ASVS
Pinning
Injection
Transaction authorization
Credential Stuffing Prevention
REST Security Cheat Sheet
Authentication Cheat Sheet
Forgot Password Cheat Sheet
Session Management Cheat Sheet
Weak Token
SSRF
File Upload Security
Input Validation Cheat Sheet
GraphQL Cheat Sheet
Query Parametrization
AWS Security
AWS Misconfigurations
PreviousHow to Hack & Protect Flutter Apps — OWASP MAS and RASP. (Pt. 2/3)NextfreeRASP meets Cordova
Last updated
Was this helpful?

