NewStart your first free run
black box vs grey box vs white box

Black box, grey box or white box: how much a pentest gets to see.

A URL, a set of logins or the repository. Each one lets the agent reach further into the application, and all three are held to the same rule: nothing is reported until it is proven against the running app.

01 / The three approaches

One agent, three starting points.

What you hand over decides where the test starts. The agent, the standard of proof and the report stay the same.

Black box

A URL, and what an outsider can reach.

The agent maps what is reachable from the internet, follows every route it can find and registers its own account where signup is open. It answers one question precisely: what can someone with no access and no inside knowledge get to?

  • Only the target URL to set up
  • Its own accounts wherever signup is open
Scan modes
highF-2B7E90C1Password reset token accepted twice
Re-test
Asset app.acme.io
EndpointPOST /api/auth/reset
CVSS 3.18.1
Observation

The token from a completed reset, replayed two hours later:

Request · Response
POST /api/auth/reset HTTP/2
{"token":"rt_91f4…","password":"••••••"}
HTTP/2 200
{"status":"password_updated"}
Signed in with the new password
Grey box

Logins for the roles that matter.

Add test accounts as headers or a cookie jar and the agent tests everything behind the login. With two roles or two tenants it can be both at once, which is how one customer reading another customer's data gets caught.

  • Bearer tokens, API keys or session cookies, encrypted at rest
  • Where broken access control turns up
Authenticated testing
Auth profiles · HTTP headers
Two tenants, replayed on every call
AL[email protected] Authorization: Bearer eyJhbGci…Q1
BO[email protected] Authorization: Bearer eyJhbGci…7x
criticalAny user can read another customer's orderWSTG-ATHZ-04
Observation
1GET /v2/orders/8842 HTTP/2
2Authorization: Bearer eyJhbGci…7x # bob
3
4HTTP/2 200
5{"id":8842,"customer":"[email protected]",
6 "total":"1,240.00","card_last4":"4417"}
White box

The repository, read after the exploit.

Connect GitHub, GitLab or Bitbucket. The agent still proves each finding against the running application, then reads the code behind it, so the finding names the file and the line and the fix arrives as a pull request. Committed secrets and the dependencies you ship come into scope as well.

  • Against your deployment, or one built from the repository
  • Everything black box and grey box reach, plus the source
White box pentest
highF-7BB9DDDEPath traversal in invoice attachment download
FindingSuggested fixAIActivity3Notes
Observation
1GET /api/invoices/INV-2201/attachment?file=../../../etc/passwd
2HTTP/2 200
3root:x:0:0:root:/root:/bin/bash

The handler joins the query parameter onto the upload directory without normalising it:

src/invoices/attachments.ts: 22 - 26
22export async function download(req, res) {
23 const invoice = await findInvoice(req.params.id);
24 const filePath = path.join(UPLOAD_DIR, req.query.file);
25 return res.sendFile(filePath);
26}
02 / Side by side

What each one needs, and what comes back.

Each step keeps everything the one before it reaches. Moving from black box to white box loses nothing.

Black box
Grey box
White box
What you provide
A URL
A URL and test accounts
A repository
Code paths tested
Those reachable from outside
Those reachable signed in
Every path in the source
Chained flaws that lead to criticals
Inferred from behaviour
Inferred from behaviour
Traced through the code
The public attack surface
Everything behind the login
Where signup is open
Access control between the roles you define
How each finding is proven
Request and response
Request and response
Request and response, plus the code that caused it
The file and line behind each finding
Committed secrets and vulnerable dependencies
The fix opened as a pull request
Works on applications you have no code for
03 / Which one to run

Pick by what you can share.

The mode is set per run, so one application can run more than one of them.

You have the source

Run white box. It covers everything the other two reach and adds the code path, committed secrets, dependencies and the fix as a pull request.

You have logins, but not the code

Run grey box. A vendor application, a partner's API or a system whose repository sits with another team: test accounts still reach everything a signed-in user can.

You have only a URL

Run black box for the outsider's view of your public surface, or as a first run before test accounts or a repository are connected.

04 / Questions

Questions, answered.

ready when you are

Start with a URL. Add logins and the repository later.

A URL is enough for the first run. Add test accounts or connect the repository whenever you are ready, and the next run reaches further.