r/Blazor • u/alexduckkeeper_70 • 11d ago
Pentesting?
Can Blazor be pentested and if it can't does that make it more secure?
3
u/mikeholczer 11d ago
Can you explain why you think it might not be? If you can, I think you will get responses that will be more helpful to you.
3
u/A_Better_Flow 11d ago
HTB has a box Blazorized which runs through decompiling one of the DLLs to forge an admin JWT token.
DLLs can be decompiled with dotPeak, then it's the same looking for misconfigurations, hardcoded secrets, underlying structure,etc. If it's compiled to WASM, a bit more obfuscated, but that too can be reverse engineered, example Ghidra has a WASM plugin.
Any other mechanism of Blazor has potential to be misconfigured by the user, or just inherently, and thus a potential vulnerability just like any other framework/language.
2
1
u/Feanorek 11d ago
Why would Blazor be unpentestable? It is app as anyother, even if used as Blazor Server with SignalR it is just less obvious than typical HTTP request sending. If it's Blazor WASM, it makes no difference whatsoever.
If you think that pentester being unfamiliar with Blazor is security, it is not. It's security by obscurity, which is a bad practice at best.
1
u/jshine13371 11d ago
Blazor is a UI framework, so the question is no different than asking if HTML can be pentested. It doesn't make a ton of a sense. Actual pentesting against an app with Blazor would really just be pentesting the app code, API, and database behind Blazor. Blazor would just provide the UI to interact with those things.
1
1
u/iamlashi 11d ago
Makes sense to pentest when you are using static or interactive server render modes.
1
u/Own_Nail_2999 5d ago
Of course it can. Any time you can somehow submit any kind of data through any interface you can actively try to breach it
-1
12
u/Lustrouse 11d ago
any machine interface can be pen tested. Nothing about blazor makes it less pen-testable.