http://g7ejphhubv5idbbu3hb3wawrs5adw7tkx7yjabnf65xtzztgg4hcsqqd.onion/html/defcon-23/dc-23-workshops-schedule.html
It’s simple to test for common vulnerabilities with a few free tools: Android Studio, Genymotion, Burp, and apktool. We will test for insecure network transmission, insecure local storage, and insecure logging. But the most common problem is failure to verify app signatures, so that apps can be modified and Trojan code can be added.