Report Items Checklist
Ensure all required items are included in the penetration test report.
Executive Summary Items
- Overall security posture assessment
- Critical and high findings count
- Key risk areas identified
- Immediate action items
- Comparison to industry standards (if applicable)
- Testing scope summary
- Testing timeline
Methodology Section
- Testing approach described
- Tools and techniques listed
- OWASP MASTG reference
- Test coverage summary
- Limitations and exclusions
Findings Documentation
For Each Finding Include:
- Unique finding ID
- Descriptive title
- Severity rating (Critical/High/Medium/Low/Info)
- CVSS score (optional)
- Affected component/location
- Description of vulnerability
- Technical details
- Steps to reproduce
- Evidence (screenshots, logs, code snippets)
- Impact statement
- Remediation recommendation
- OWASP MASTG reference
- CWE reference
Finding Template
## [FINDING-001] Sensitive Data in Plaintext SharedPreferences
**Severity**: High
**CVSS**: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
**Location**: /data/data/com.target.app/shared_prefs/auth.xml
**MASTG**: MASTG-TEST-0001
**CWE**: CWE-312 (Cleartext Storage of Sensitive Information)
### Description
Authentication tokens are stored in plaintext in SharedPreferences,
allowing any application with root access or backup capability to
extract user credentials.
### Technical Details
The application stores JWT authentication tokens in SharedPreferences
without encryption:
- File: auth_prefs.xml
- Key: auth_token
- Value: eyJhbGciOiJIUzI1NiIs...
### Steps to Reproduce
1. Install application and log in
2. Run: adb shell "su -c 'cat /data/data/com.target.app/shared_prefs/auth.xml'"
3. Observe plaintext token in output
### Evidence
[Screenshot or code snippet]
### Impact
An attacker with device access or backup capability can:
- Extract authentication tokens
- Impersonate users
- Access sensitive account data
### Remediation
1. Use Android Keystore for sensitive data storage
2. Implement EncryptedSharedPreferences
3. Set tokens to expire after reasonable periodEvidence Requirements
Screenshots
- Application version/info screen
- Vulnerable configuration
- Exploitation proof
- Sensitive data exposure
- Error messages
Technical Evidence
- HTTP requests/responses
- Frida script output
- Log entries
- Database contents
- File contents
- Code snippets (decompiled)
Video (if applicable)
- Complex exploitation steps
- Time-sensitive vulnerabilities
- Authentication bypass
Severity Classification
Use Consistent Ratings
| Severity | Description | Examples |
|---|---|---|
| Critical | Remote compromise, data breach | RCE, SQL injection, hardcoded keys |
| High | Significant security impact | Auth bypass, plaintext credentials |
| Medium | Moderate security risk | Missing pinning, weak crypto |
| Low | Minor security issues | Missing headers, info disclosure |
| Info | Best practice recommendations | Obfuscation suggestions |
Risk Assessment
- Overall risk rating
- Business impact analysis
- Likelihood assessment
- Risk matrix included
Risk Matrix
Impact
High | Medium | High | Critical
Medium | Low | Medium | High
Low | Info | Low | Medium
+--------------------------
Low Medium High
LikelihoodRemediation Section
For Each Finding
- Specific fix recommendation
- Code examples (if applicable)
- Reference documentation
- Priority/timeline suggestion
Overall Recommendations
- Short-term fixes (critical issues)
- Medium-term improvements
- Long-term security enhancements
- Security awareness recommendations
Appendices
Required Appendices
- Appendix A: Tool list and versions
- Appendix B: Testing timeline
- Appendix C: Raw evidence (if separate)
- Appendix D: OWASP MASTG mapping
- Appendix E: Glossary
Optional Appendices
- Full Frida scripts used
- Complete HTTP traffic logs
- Database dumps (sanitized)
- Decompiled code excerpts
Quality Checks
Before Submission
- All findings have complete documentation
- Screenshots are clear and annotated
- Technical accuracy verified
- Grammar and spelling checked
- Sensitive data redacted appropriately
- Client information accurate
- Page numbers and TOC updated
- Report reviewed by peer (if applicable)
Sensitive Data Handling
- Test credentials redacted
- Personal data anonymized
- API keys/tokens masked
- Internal IPs/hostnames sanitized
Report Deliverables
Primary Deliverables
- Executive Summary (PDF)
- Technical Report (PDF)
- Finding Spreadsheet (Excel/CSV)
Supporting Materials
- Evidence archive (ZIP)
- Remediation guide
- Presentation slides (if required)
Finding Categories Summary
Ensure findings are categorized properly:
MASVS-STORAGE
- Insecure data storage findings
- Backup vulnerabilities
- Logging issues
MASVS-CRYPTO
- Weak cryptography
- Key management issues
- Random number issues
MASVS-AUTH
- Authentication bypass
- Session management
- Biometric issues
MASVS-NETWORK
- Cleartext traffic
- TLS configuration
- Certificate pinning
MASVS-PLATFORM
- IPC vulnerabilities
- WebView issues
- Deep link issues
MASVS-CODE
- Debug configuration
- Code quality issues
- Reverse engineering
Sign-Off
- Technical reviewer sign-off
- Quality assurance review
- Final approval
- Client delivery confirmed