Desktop applications, also known as fat or thick clients, remain a business-critical attack surface in many enterprise environments, especially in finance, insurance, and pharmaceuticals. Testing them requires a different approach than classic web application testing: reverse engineering client-side functionality, understanding proprietary protocols, and analyzing backend communication. This hands-on training introduces a practical methodology for assessing Java desktop applications from initial analysis to backend exploitation. Participants will reverse engineer a demo application, inspect its network communication, build a custom pentest client, and use it to identify and exploit server-side vulnerabilities.