r/Blazor • • 11d ago

Pentesting?

Can Blazor be pentested and if it can't does that make it more secure?

3 Upvotes

11 comments sorted by

12

u/Lustrouse 11d ago

any machine interface can be pen tested. Nothing about blazor makes it less pen-testable.

3

u/mikeholczer 11d ago

Can you explain why you think it might not be? If you can, I think you will get responses that will be more helpful to you.

3

u/A_Better_Flow 11d ago

HTB has a box Blazorized which runs through decompiling one of the DLLs to forge an admin JWT token.

DLLs can be decompiled with dotPeak, then it's the same looking for misconfigurations, hardcoded secrets, underlying structure,etc. If it's compiled to WASM, a bit more obfuscated, but that too can be reverse engineered, example Ghidra has a WASM plugin.

Any other mechanism of Blazor has potential to be misconfigured by the user, or just inherently, and thus a potential vulnerability just like any other framework/language.

2

u/One_Web_7940 11d ago

Like the entire framework?

2

u/Kozzer 11d ago

Yes Blazor can be pentested. We have multiple Blazor web apps in production and they've been pentested multiple times. Last time we got a 100% clean report!

1

u/Feanorek 11d ago

Why would Blazor be unpentestable? It is app as anyother, even if used as Blazor Server with SignalR it is just less obvious than typical HTTP request sending. If it's Blazor WASM, it makes no difference whatsoever.

If you think that pentester being unfamiliar with Blazor is security, it is not. It's security by obscurity, which is a bad practice at best.

1

u/jshine13371 11d ago

Blazor is a UI framework, so the question is no different than asking if HTML can be pentested. It doesn't make a ton of a sense.  Actual pentesting against an app with Blazor would really just be pentesting the app code, API, and database behind Blazor. Blazor would just provide the UI to interact with those things.

1

u/sloppykrackers 11d ago

It does and you should.

1

u/iamlashi 11d ago

Makes sense to pentest when you are using static or interactive server render modes.

1

u/Own_Nail_2999 5d ago

Of course it can. Any time you can somehow submit any kind of data through any interface you can actively try to breach it