Overview
Thick client applications — trading terminals, ERP clients, healthcare systems, point-of-sale and internal tools — often hold sensitive data and talk directly to databases or backend services. Because they run on the user's machine, attackers can inspect, modify and replay everything the client does.
Our testers analyse the application binary and its local files, intercept and manipulate traffic (including non-HTTP protocols), inspect memory for secrets, test for DLL hijacking and insecure update mechanisms, and attack the backend services the client depends on.
The most serious issues are usually trust problems: business rules enforced only in the client, credentials or connection strings stored locally, and servers that accept whatever the client sends.
What's included
Our approach
- UnderstandArchitecture, roles and backend dependencies.
- AnalyseStatic and dynamic analysis of the client.
- InterceptTraffic interception and manipulation.
- Attack backendTest servers and databases the client uses.
- Report & retestFindings with fixes for client and server teams.
What you receive
- Client and server findings
- Proof-of-concept evidence
- Architecture-level recommendations
- Retest report
- Attestation letter
Standards & frameworks
- OWASP Desktop App Security Top 10
- OWASP ASVS
- CWE
- PTES
Frequently asked questions
What is a thick client?
A desktop application that performs significant processing locally and communicates with backend servers, as opposed to a browser-based thin client.
Do you need a test environment?
Yes, ideally a test instance of the client and backend with test accounts for each role.
Can you test proprietary protocols?
Yes. We analyse and manipulate non-HTTP traffic where needed.