Black-box and grey-box testing
In black-box testing the tester knows only the target address; in grey-box testing test accounts are provided and what a signed-in user can reach is examined as well.
- 01
Why it matters
The type of test sets how much information and access the tester starts with, and it directly shapes the result. Black-box testing imitates an outside attacker with no knowledge. In grey-box testing test accounts are provided, so the test also checks whether a signed-in user, such as a customer or an employee, can step outside their permissions.
- 02
Example
In a black-box test the tester knows only the domain and works on what is visible before sign-in. In a grey-box test they get a customer account and check whether it can reach other customers' invoices.
- 03
Common mistake
Asking for black-box testing only to save budget. Many real breaches move on from a stolen or weak account; if the area behind sign-in is not tested, the riskiest part stays unseen.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.