Application Security Analysis

Reverse engineer application to understand internal structure
Fuzz and inject malformed data to discover security issues
Write exploit or proof-of-concept code to validate the vulnerability
Software vulnerability is responsible for a majority of security breaches. The unstoppable growth of digital transformation makes software security even more important as hackers constantly attack and exploit vulnerable applications to infiltrate an organization. Despite its criticality, software are still buggy and vulnerable to all kind of attacks owing to the lack of software quality assurance and testing.
In contrary to Secure Code Review service where source code is required for security analysis, ECQ offers Application Security Analysis service to test closed source or proprietary software for potential security issues. The service is offered from a Black Box point of view where no source code or internal structure of the software is provided.
The following describes three major activities that are normally involved.