What is Detectify?
Web security blog
Security
Writeups
How to
Detectify
Abuse MITM possible regardless of HTTPS
featured
https
mitm
vpn
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
XSS using quirky implementations of ACME http-01
Auditor
Cross Site Scripting
featured
Frans Rosén
HTTPS Everywhere
Linus Särud
validation
Bypassing and exploiting Bucket Upload Policies and Signed URLs
AWS
bug bounty
Cloud Security
featured
Frans Rosén
Google Cloud
s3 buckets
The danger of recycled phone numbers
2fa
phone number
Scratching the surface of host headers in Safari
host headers
password managers
Safari
XSS
GraphQL abuse: Bypass account level permissions through parameter smuggling
Detectify Crowdsource
Changing the URL of social media sharing buttons
open redirect
phishing
social media
Using Google Analytics for data extraction
CSP
Detectify Crowdsource
Google Analytics
How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting
Security Questions are not secure
Amazon
PayPal
Public Information
Security Questions
1
2
3
…
7
Next »