Applications that are installed locally on our computers. Unlike thin client applications that run on a remote server and can be accessed through the web browser, these applications do not require internet access to run. Examples of these include project management systems, customer relationship management systems, inventory management tools and other productivity software.

Many of these applications include a sandbox, which is a virtual environment that allows untrusted code, such as code downloaded from the internet, to run safely on a user’s system. It isolates ntrusted code, preventing form accessing or modifying system resources.

In .NET environments, a thick client is known as a rich client or fat client, referring to an application that performs a lot of processing on the client side.

Thick client applications can be categorized into

  • two tier architecture where the application is installed locally on the computer and communicates directly with the database.
  • three tier architecture where they first communicate with an application server and then interact with the database.

Thick client application are considere less secure than web application.

Penetration Testing Process

Thick client application penetration testing is considerably different than typical processes.

Information Gathering

We first have to identify the application architecture, the programming language and frameworks that have been used, and understand how the application and the infrastructure work.

Client Side Attacks

Sensitive information like usernames and passwords, tokens or strings for communication with other services might be stored in the application’s local files.

Network Side Attacks

Network traffic analysis will help us capture sensitive information that might be transferred through HTTP/HTTPS or TCP/UDP connection.

Retrieving Hardcoded Credentials

In windows we can use the ProcMon from Sysinternals to monitor the process and see what the executable is doing.

In order to capture files made by a program we need to change the permissions of the files being created to disallow deletions.

Properties -> Security -> Advanced -> cybervaca -> Disable inheritance -> Convert inherited permissions into explicit permissions on this object -> Edit -> Show advanced permissions, we deselect the Delete subfolders and files, and Delete checkboxes.

If we are stuck at any point with ProcMon we can then try with x64dbg to view what instructions are being sent.

Memory mapped files allow application to access large files without having to read or write the entire file into memory at once. Instead the file is mapped to a region of memory that the application can read and write as if it were a regular buffer. This is a good place to look for hardcoded credentials.

We can export items from memory into a memory dump by selecting the Dump Memory to File. Running strings on the exported file reveals some interesting information.

C:\TOOLS\Strings\strings64.exe .\restart-service_00000000001E0000.bin

If we notice some indication of a being .NET executable we can De4Dot to reverse the .NET executable back to the source code.

Web Vulnerabilities

Three tier architecture applications can be susceptible to web-specific attacks like SQL injection and Path Traversal.

We can check what type of requests our thick client is making via Wireshark packet capture.

JD-GUI is a helpful tools for decompiling java applications.