PostNL created a mobile application for track & trace of packages for their business-customers. In order to ensure the security of the data of both customers as well as packages PostNL requested me execute a penetration test on the mobile app for both Android as well as IOS.
The scope of this test was limited to a grey-box penetration test of the apps themselves, and not of the services and API’s supporting the app.