Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Releasing an app with its android:debuggable attribute set to true can leak sensitive information. In addition, the app is vulnerable to decompilation, resulting in alteration to source code.Attackers can leverage the additional information they gain from debugging output to mount attacks targeted on the framework, database, or other resources used by the application.

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

DRD10-J

High

Probable

Low

P18

L1

...

 TBD (e.g., MITRE CWE) 

Bibliography

ASP.NET Misconfiguration: Creating Debug Binary http://www.ids-sax2.com/Knowledgebase/NetworkSecurity/Creating-Debug-Binary.htm[TBD] 

 

...