Call For Paper - Workshops

Desktop Application Pentesting 101 for Security Professionals
2026-09-11 , Uni Campus Seminarhaus 2

Desktop applications, also known as fat or thick clients, remain a business-critical attack surface in many enterprise environments, especially in finance, insurance, and pharmaceuticals. Testing them requires a different approach than classic web application testing: reverse engineering client-side functionality, understanding proprietary protocols, and analyzing backend communication. This hands-on training introduces a practical methodology for assessing Java desktop applications from initial analysis to backend exploitation. Participants will reverse engineer a demo application, inspect its network communication, build a custom pentest client, and use it to identify and exploit server-side vulnerabilities.


This workshop gives security professionals practical experience with desktop application penetration testing. After a short introduction and environment setup, participants learn how to fingerprint technologies, decompile a Java client, analyze client-server communication, and understand why backend systems often represent the real security boundary. The core hands-on part focuses on building a custom client that communicates directly with the backend, bypassing limitations of the original application. Participants then use this client and the knowledge gained from static and network-level analysis to hunt for vulnerabilities and exploit them in a realistic lab environment.

Jakob Steeg is a security consultant and penetration tester at usd AG with several years of experience in planning and executing penetration tests across web applications, APIs, cloud environments, Kubernetes, Windows/Active Directory, mobile platforms, and native/thick client applications. He specializes in the security assessment of desktop clients and proprietary or binary protocols, applying his strong software development background to build custom testing tools and analyze complex systems. His expertise includes cryptographic mechanisms, secure software development, public key infrastructures, and modern network architectures. Jakob holds a Master’s degree in IT Security from TU Darmstadt, is OSCP and OSWE certified, and has published multiple CVE-listed vulnerabilities.

Tim Kranz is a managing consultant and penetration tester at usd AG.