~/services/thick-client-testingService
Thick client application testing
An assessment of a desktop application and everything it talks to. A thick client keeps logic, secrets and trust on a machine the user controls, which is a different problem from a web application that holds all of that on the server, and it is tested differently.
What we look for
- Full coverage of the client, the machine it runs on and the services behind it, applied to how the application is actually deployed
- Authentication, session and licensing logic that executes somewhere the user can change it
- Authorization decisions the client assumes rather than the server enforcing
- Secrets, credentials and configuration recoverable from the binary, from memory and from disk
- The transport and protocol between client and server, including proprietary and binary formats
- Local privilege escalation through the installer, services, file permissions and the update mechanism
- Reverse engineering and tampering resistance, wherever the client is relied on to enforce something
- Coverage spans the client, the host and the backend, not the interface alone
What you receive
- Executive summary
- Technical findings with reproduction steps
- Working proof of exploit per finding
- Developer-ready remediation
- Report walkthrough call
- Retest included
Get a fixed price for this.
A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.