|
The same Web security rules apply regardless of the client being used. The good news is that exploitation via phone is not quite as easy or convenient. The bad news is that the mobile-centric pages are still accessible to everyone on the Web. The best recommendation is to find and fix the flaws in your existing code before your port it over to the mobile world. For those who've already gone mobile be sure to include the mobile code in your security testing. Even though it may look the same there could be some nuances that lead to security flaws.
Here are some articles I can recommend for testing rich internet applications, Web 2.0 and other online security concerns:
|