← All tools

ridhinva/mobile-iot-scanner

Popularity 65 Updated Testing & Security

Scanner: Mobile/IoT security scanner — Android exported components, iOS URL schemes, BLE pairing, MQTT/CoAP exposure in Python

githubauto-collected

Installation

A directly usable install command is not verified yet. Check the project documentation or releases.

Mobile/IoT Security Scanner

<p align="center" </p

---

🎯 Overview

Mobile/IoT security scanner for Android exported components, iOS URL schemes, BLE pairing, MQTT/CoAP exposure, and firmware update flaws.

| Check | Severity | Description | |-------|----------|-------------| | Android Exported Components | 🔴 CRITICAL | Activity, Service, Receiver, Provider | | iOS URL Scheme Hijacking | 🟠 HIGH | Universal Links, custom schemes | | Certificate Pinning Bypass | 🟠 HIGH | Frida, Objection detection | | Insecure Data Storage | 🟠 HIGH | SharedPreferences, Keychain, SQLite | | BLE Pairing/Key Exchange | 🟡 MEDIUM | Just Works, numeric comparison | | MQTT/CoAP Exposure | 🔴 CRITICAL | Unencrypted, no auth | | Firmware Update Flaws | 🔴 CRITICAL | No signing/verification | | Hardware Debug Interfaces | 🟡 MEDIUM | JTAG, UART, SWD exposure |

---

🚀 Quick Start

git clone https://github.com/ridhinva/mobile-iot-scanner.git
cd mobile-iot-scanner
pip install requests frida-tools
python3 mobile_iot_scanner.py --target app.apk --mode android

---

⚖️ Disclaimer

For authorized security testing only.