Skip to content

Whitelisting domains in mobile scans

This video walks through creating mobile scans with whitelisted domains.

Go to report.ostorlab.co

1. Introduction

By whitelisting domains, you can allow for in-scope testing and avoid testing out-of-scope targets

Introduction

2. Click here

Initiate the process by clicking the "New Scan" icon.

New Scan Icon

3. Select the asset type

Choose the asset type. This can either be Play Store, App Store, Android APK or Android AAB, iOS IPA, or iOS Test Flight. For this example, we'll select Play Store.

Select the asset type

4. Provide the target

Provide the scan target.

Provide the target

5. Click "Continue"

Progress to the next step by clicking continue.

Click 'Continue'

6. Click "Full Scan"

Select the Full Scan option to thoroughly evaluate the security of your app against whitelisted domains.

Click 'Full Scan'

7. Click "Continue"

Confirm your choice to proceed by clicking continue.

Click 'Continue'

8. Select Test Credentials

Select the test credentials to use. This step is optional.

Select Test Credentials

9. Click "Continue"

Click continue to proceed to the next step.

Click 'Continue'

10. Provide the domains to whitelist

Enter the domains to whitelist. You can provide multiple domains by adding each one on a new line. The domains can also be provided as regular expressions.

Provide the domains to whitelist

11. Click "submit"

Finalize the creation of your mobile scan by clicking submit.

Click 'submit'

12. Click "Proceed"

Click proceed to create the scan.

Click 'Proceed'

13. Click "show"

Click Show to go to the list of scans.

Click 'show'

14. List of scans

The scan will be listed in the scans table.

List of scan

This video walked through creating mobile scans with whitelisted domains, allowing for in-scope testing and avoid testing out-of-scope targets.