40% of Android apps expose sensitive back end information
codifiedsecurity.com
codifiedsecurity.com
We looked for strings that matched certain entropy patterns common to the services listed on the site.
For staging environments we looked at likely candidates from string variable names and patterns that looked likely to be staging environments.
It's really dreadful the amount of debug/useless code that gets left in production Android apps, and it tends to grow over time.
One of the worst offenders in our sample was fintech companies, with obviously no real pentesting being done on the client side at least.