~/services/thick-client-testingService

Thick client application testing

An assessment of a desktop application and everything it talks to. A thick client keeps logic, secrets and trust on a machine the user controls, which is a different problem from a web application that holds all of that on the server, and it is tested differently.

Typical duration5 to 12 working days
RetestIncluded

What we look for

  • Full coverage of the client, the machine it runs on and the services behind it, applied to how the application is actually deployed
  • Authentication, session and licensing logic that executes somewhere the user can change it
  • Authorization decisions the client assumes rather than the server enforcing
  • Secrets, credentials and configuration recoverable from the binary, from memory and from disk
  • The transport and protocol between client and server, including proprietary and binary formats
  • Local privilege escalation through the installer, services, file permissions and the update mechanism
  • Reverse engineering and tampering resistance, wherever the client is relied on to enforce something
  • Coverage spans the client, the host and the backend, not the interface alone

What you receive

  • Executive summary
  • Technical findings with reproduction steps
  • Working proof of exploit per finding
  • Developer-ready remediation
  • Report walkthrough call
  • Retest included

Get a fixed price for this.

A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.