Across industries and sizes, thick client applications have been around for many years. The adoption of hybrid infrastructure architecture can make thick-client applications more attractive to attackers. During a thick client pentest, both local and server-side processing is involved, as well as proprietary communication protocols
Since security testing is often focused on web and mobile applications, thick client applications aren't usually thoroughly tested. A variety of vulnerabilities can be found in thick client apps that may compromise your systems completely.
Through our Thick Client Security Assessment service, we will explore the security holes in thick client applications on behalf of our clients. We begin our assessments with two approaches.
An analysis of your thick client software and server-side APIs based on a risk-based approach. Our approach involves automated scanning of the thick client application, configuration analysis, network traffic analysis, client and server-side validation checks, and binary analysis in order to identify potential business logic vulnerabilities.