Penetration Test of GWT-based Web Applications
As part of several projects, we tested web applications built with the Google Web Toolkit (GWT). This technology is commonly used in administrative and specialized applications and is characterized by complex, highly serialized communication between browser and server. Traditional automated testing approaches, such as those using Burp Suite, can only be applied to a limited extent, as the communication is often proprietary or additionally encrypted.
The assessment therefore requires a deep understanding of the underlying architecture. A significant portion of the work involves manual testing to interpret data structures, analyze protocols, and derive potential attack vectors. While manual verification is also part of a typical web application pentest, such tests can usually be supported extensively by automation. In GWT-based applications, however - especially when communication between client and server is encrypted - this is barely feasible. In the end, the analysis is largely manual. Or, as one of our pentesters aptly put it: “You just have to think.”
Talk now
to our
Pentest experts.
Contact us
OSCP, M.Sc. Security Management
Talk now to our Pentest experts.
OSCP, M.Sc. Security Management
Penetration Testing
Since 2013, we have been conducting professional penetration tests. All engagements are performed in accordance with international standards and backed by years of operational experience in penetration testing, red teaming, and offensive security. Originally rooted in the payment, finance, and banking sector, we bring extensive experience in highly regulated and security-critical environments.
As a specialized provider for professional penetration testing, we clearly distinguish between vulnerability scans and actual penetration testing. Tools are used selectively and interpreted within a clear methodology. However, decisive insights usually result from structured manual identification and analysis. We identify technical and business-critical weaknesses and subsequently assess them in a structured way based on their real-world risk. Looking for a professionally conducted penetration test with traceable results? Then binsec is your partner.
Contact us