thick-client
Authorized security testing of desktop thick clients: local storage, update channels, IPC, traffic interception, and client-side trust-boundary revi…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
> ⚠️ AUTHORIZED USE ONLY
> This skill is for educational purposes or authorized security assessments only.
> You must have explicit, written permission from the system owner before using this tool.
> Misuse of this tool is illegal and strictly prohibited.
> Mandatory confirmation gate
> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
> 1. Ask the user to state the exact target URL, IP, account, or resource.
> 2. Ask the user to confirm written authorization and the permitted scope.
> 3. Show the exact command(s) and explain their expected effect.
> 4. Wait for explicit confirmation in the current conversation.
>
> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
Thick Client Security Testing
When to Use
- Assessing a desktop application's security posture.
- Checking whether client-side trust decisions can be subverted.
适用场景
- C/S 架构客户端、Electron/Qt/.NET WinForms/WPF
- 本地配置/凭证存储、IPC、命名管道
- 客户端强制校验绕过研究(授权)
- 自动更新通道与代码签名验证
工作流
1. 建边界
□ 进程树、子进程、驱动/服务
□ 监听端口与出站域名
□ 本地敏感路径:%APPDATA%、Keychain、注册表
2. 本地攻击面
□ 明文配置、硬编码密钥、调试开关
□ DLL 劫持/搜索顺序(Windows)
□ 数据库文件(SQLite)权限与加密
□ IPC:谁可连接?是否鉴权?
3. 网络面
□ 系统代理 / 应用自定义 TLS
□ 证书钉扎 → 联合 mobile/js 方法学或 Frida
□ API 越权:客户端隐藏的管理接口
4. 逆向验证
□ .NET → dotnet-reverse;原生 → ida/ghidra;Electron → asar + js-reverse
工具链
| 工具 | 用途 |
|------|------|
| Process Monitor / API Monitor | 行为 |
| Burp / mitmproxy | 流量 |
| dnSpy / IDA / Ghidra | 逆向 |
| Sysinternals | Windows 面 |
| asar / nexe 检测 | Electron |
参考
references/thick-client-checklist.md../dotnet-reverse/../ida-reverse/../js-reverse/../api-security/
路由上下文
上游: MASTER R32
下游: 纯协议 protocol-reverse;供应链更新 supply-chain-security
任务完成自检
- [ ] 是否画出信任边界?
- [ ] 本地+网络面是否都覆盖?
- [ ] Checklist?
Limitations
- .NET/Java clients need framework-specific tooling.
- Server-side enforcement gaps found client-side still need server confirmation.
> Adapted from zhaoxuya520/reverse-skill (MIT).
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/agentic-awesome-skills-claude/skills/thick-client/SKILL.md同一个仓库里的其他技能
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 thick-client 的技能。它们内容并不相同,别混用:
- sickn33/agentic-awesome-skills — Authorized security testing of desktop thick clients: local storage, update channels, IPC,
- sickn33/agentic-awesome-skills — Authorized security testing of desktop thick clients: local storage, update channels, IPC,